CVE-2006-3921: Medium severity Sun ONE Application Server vulnerability
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3921?
CVE-2006-3921 is considered a medium severity vulnerability as it allows authenticated users to read unauthorized files.
How do I fix CVE-2006-3921?
To fix CVE-2006-3921, update to a fixed version of the Sun Java System Application Server or Web Server that addresses this issue.
Who is affected by CVE-2006-3921?
CVE-2006-3921 affects users of Sun Java System Application Server versions 7 through 8.1 and Sun Java System Web Server versions 6.0 and 6.1.
What is the impact of CVE-2006-3921?
The impact of CVE-2006-3921 is that remote authenticated users can read files outside of the document root directory, potentially exposing sensitive data.
Is CVE-2006-3921 still a concern today?
Although CVE-2006-3921 was reported in 2006, it remains a concern for legacy systems that continue to run affected versions without updates.