First published: Fri Aug 18 2006(Updated: )
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | <=6.0.2.11 | |
Ibm Websphere Application Server | =6.0.2 | |
Ibm Websphere Application Server | =6.0.2.1 | |
Ibm Websphere Application Server | =6.0.2.3 | |
Ibm Websphere Application Server | =6.0.2.5 | |
Ibm Websphere Application Server | =6.0.2.7 | |
Ibm Websphere Application Server | =6.0.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.