First published: Tue Jun 27 2006(Updated: )
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server with Web Server Plug-ins | =2.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0.2.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0.2.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0.2.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.0.2.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.5.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.5.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =3.5.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =4.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =4.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.11 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.12 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.13 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.14 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.15 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.0.2.16 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =5.1.1.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =6.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =6.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =6.0.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-3231 is considered high as it allows remote attackers to access sensitive information.
To fix CVE-2006-3231, upgrade IBM WebSphere Application Server to version 6.0.2.11 or later.
CVE-2006-3231 affects multiple versions of IBM WebSphere Application Server prior to 6.0.2.11.
CVE-2006-3231 can potentially expose JSP source code and other sensitive information through specially crafted URIs.
A temporary workaround for CVE-2006-3231 is to disable file serving within the IBM WebSphere Application Server configuration.