Lucene search

K
nvd[email protected]NVD:CVE-2006-6637
HistoryDec 19, 2006 - 8:28 p.m.

CVE-2006-6637

2006-12-1920:28:00
CWE-200
web.nvd.nist.gov
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.009

Percentile

83.0%

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via “specific requests.”

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch6.0.2.1
OR
ibmwebsphere_application_serverMatch6.0.2.3
OR
ibmwebsphere_application_serverMatch6.0.2.5
OR
ibmwebsphere_application_serverMatch6.0.2.7
OR
ibmwebsphere_application_serverMatch6.0.2.9
OR
ibmwebsphere_application_serverMatch6.0.2.11
OR
ibmwebsphere_application_serverMatch6.0.2.13
OR
ibmwebsphere_application_serverMatch6.0.2.15
VendorProductVersionCPE
ibmwebsphere_application_server6.0.2.1cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.3cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.5cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.7cpe:2.3:a:ibm:websphere_application_server:6.0.2.7:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.9cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.11cpe:2.3:a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.13cpe:2.3:a:ibm:websphere_application_server:6.0.2.13:*:*:*:*:*:*:*
ibmwebsphere_application_server6.0.2.15cpe:2.3:a:ibm:websphere_application_server:6.0.2.15:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.009

Percentile

83.0%

Related for NVD:CVE-2006-6637