PT-2001-1657 · Ibm · Application Server+1

Published

2001-05-24

·

Updated

2016-10-18

·

CVE-2001-0446

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Commerce Suite version 4.0.1 with Application Server 3.0.2
Description The issue allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
Recommendations For IBM WebSphere Commerce Suite version 4.0.1 with Application Server 3.0.2, consider restricting access to .jsp files to prevent source code disclosure until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0446

Affected Products

Application Server
Ibm Websphere Commerce Suite