Vulnerability Description
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | All versions |
| Unix | Unix | All versions |
| Ibm | Websphere Application Server | 5.0.1 |
References
- http://www-1.ibm.com/support/docview.wss?uid=swg24013029PatchVendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24013029PatchVendor Advisory
FAQ
What is CVE-2006-7164?
CVE-2006-7164 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers...
How severe is CVE-2006-7164?
CVE-2006-7164 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-7164?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Unix Unix, Ibm Websphere Application Server.