First published: Fri May 19 2006(Updated: )
BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2466 is considered a critical vulnerability due to its potential to expose source code of JSP pages to remote attackers.
To mitigate CVE-2006-2466, upgrade to a patched version of BEA WebLogic Server that addresses this vulnerability.
CVE-2006-2466 affects BEA WebLogic Server versions 8.1 up to SP4 and 7.0 up to SP6.
CVE-2006-2466 can be exploited by remote attackers to obtain sensitive JSP source code during specific error conditions.
While it primarily affects older versions of WebLogic Server, any legacy systems running these versions remain at risk from CVE-2006-2466.