First published: Mon May 17 2010(Updated: )
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =6.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.1.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.16 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.18 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.20 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.22 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.24 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.28 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.30 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.31 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.32 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.33 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.35 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.37 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.0.2.39 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.9 | |
=6.0 | ||
=6.0.0.1 | ||
=6.0.0.2 | ||
=6.0.0.3 | ||
=6.0.1 | ||
=6.0.1.1 | ||
=6.0.1.2 | ||
=6.0.1.3 | ||
=6.0.1.5 | ||
=6.0.1.7 | ||
=6.0.1.9 | ||
=6.0.1.11 | ||
=6.0.1.13 | ||
=6.0.1.15 | ||
=6.0.1.17 | ||
=6.0.2 | ||
=6.0.2.1 | ||
=6.0.2.2 | ||
=6.0.2.3 | ||
=6.0.2.4 | ||
=6.0.2.5 | ||
=6.0.2.6 | ||
=6.0.2.7 | ||
=6.0.2.8 | ||
=6.0.2.9 | ||
=6.0.2.10 | ||
=6.0.2.11 | ||
=6.0.2.12 | ||
=6.0.2.13 | ||
=6.0.2.14 | ||
=6.0.2.15 | ||
=6.0.2.16 | ||
=6.0.2.17 | ||
=6.0.2.18 | ||
=6.0.2.19 | ||
=6.0.2.20 | ||
=6.0.2.21 | ||
=6.0.2.22 | ||
=6.0.2.23 | ||
=6.0.2.24 | ||
=6.0.2.25 | ||
=6.0.2.27 | ||
=6.0.2.28 | ||
=6.0.2.29 | ||
=6.0.2.30 | ||
=6.0.2.31 | ||
=6.0.2.32 | ||
=6.0.2.33 | ||
=6.0.2.35 | ||
=6.0.2.37 | ||
=6.0.2.39 | ||
=6.1 | ||
=6.1.0 | ||
=6.1.0.0 | ||
=6.1.0.1 | ||
=6.1.0.2 | ||
=6.1.0.3 | ||
=6.1.0.5 | ||
=6.1.0.7 | ||
=6.1.0.9 | ||
=6.1.0.11 | ||
=6.1.0.13 | ||
=6.1.0.15 | ||
=6.1.0.17 | ||
=6.1.0.19 | ||
=6.1.0.21 | ||
=6.1.0.23 | ||
=6.1.0.25 | ||
=6.1.0.27 | ||
=6.1.0.29 | ||
=7.0 | ||
=7.0.0.1 | ||
=7.0.0.3 | ||
=7.0.0.5 | ||
=7.0.0.7 | ||
=7.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0777 has a medium severity rating, indicating potential for sensitive information disclosure.
To fix CVE-2010-0777, update IBM WebSphere Application Server to version 6.0.2.43, 6.1.0.31, or 7.0.0.11 or later.
CVE-2010-0777 affects versions of IBM WebSphere Application Server 6.0 prior to 6.0.2.43, 6.1 prior to 6.1.0.31, and 7.0 prior to 7.0.0.11.
CVE-2010-0777 is an information disclosure vulnerability due to improper handling of long filenames by the Web Container in IBM WebSphere Application Server.
Yes, CVE-2010-0777 can potentially allow remote attackers to access sensitive information.