4.3

CVE-2006-7164

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

Data is provided by the National Vulnerability Database (NVD)
IbmWebsphere Application Server Version5.0.1
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.1
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.2
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.3
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.4
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.5
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.6
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.7
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.8
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.9
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.10
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.11
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.12
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.13
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.14
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.15
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
IbmWebsphere Application Server Version5.0.2.16
   LinuxLinux Kernel Editionia32_64-bit
   UnixUnix
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.392
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N