PT-2007-1442 · Ibm · Ibm Websphere Application Server

Published

2007-03-20

·

Updated

2008-09-05

·

CVE-2006-7164

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 5.0.1 through 5.0.2.7
Description The issue concerns the SimpleFileServlet in IBM WebSphere Application Server, which fails to block certain invalid URIs and does not issue a security challenge. This allows remote attackers to read secure files and obtain sensitive information via certain requests.
Recommendations For IBM WebSphere Application Server versions 5.0.1 through 5.0.2.7, consider restricting access to the SimpleFileServlet until a patch is available. As a temporary workaround, limit the handling of invalid URIs to prevent unauthorized file access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7164

Affected Products

Ibm Websphere Application Server