PT-2007-1442 · Ibm · Ibm Websphere Application Server

Publicado

2007-03-20

·

Atualizado

2008-09-05

·

CVE-2006-7164

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 5.0.1 through 5.0.2.7
Description The issue concerns the SimpleFileServlet in IBM WebSphere Application Server, which fails to block certain invalid URIs and does not issue a security challenge. This allows remote attackers to read secure files and obtain sensitive information via certain requests.
Recommendations For IBM WebSphere Application Server versions 5.0.1 through 5.0.2.7, consider restricting access to the SimpleFileServlet until a patch is available. As a temporary workaround, limit the handling of invalid URIs to prevent unauthorized file access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-7164

Produtos afetados

Ibm Websphere Application Server