Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-0425

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-0425
Last Modified 05 Sep 2008 04:46:15
Published 02 May 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-0425

Summary

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

Vulnerable Systems

Application

  • Ibm Websphere Application Server 5.0

  • Ibm Websphere Application Server 5.1.0

  • Ibm Websphere Application Server 6.0


References

CONFIRM - http://www-1.ibm.com/support/docview.wss?uid=swg24008815

CONFIRM - http://www-1.ibm.com/support/docview.wss?uid=swg24008814

SECUNIA - 14274


Last Updated: 27 May 2016 10:39:48