{"api_version":"1","generated_at":"2026-07-23T12:04:06+00:00","cve":"CVE-2005-1112","urls":{"html":"https://cve.report/CVE-2005-1112","api":"https://cve.report/api/cve/CVE-2005-1112.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1112","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1112"},"summary":{"title":"CVE-2005-1112","description":"IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=111342594129109&w=2","name":"http://marc.info/?l=bugtraq&m=111342594129109&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'IBM WebSphere Widespread configuration JSP disclosure' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/15501","name":"http://www.osvdb.org/15501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/13160","name":"http://www.securityfocus.com/bid/13160","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server Web Server Root JSP Source Code Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/14962","name":"http://secunia.com/advisories/14962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - IBM WebSphere Application Server JSP Source Exposure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20099","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20099","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1013697","name":"http://securitytracker.com/id?1013697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityTracker.com Archives - IBM WebSphere May Disclose JSP Source to Remote Users Sending Invalid Host Headers","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1112","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1112","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.0.2.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"5.1.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:36:00.228Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050413 IBM WebSphere Widespread configuration JSP disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111342594129109&w=2"},{"name":"ibm-websphere-information-disclosure(20099)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20099"},{"name":"15501","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/15501"},{"name":"13160","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13160"},{"name":"1013697","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1013697"},{"name":"14962","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14962"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-04-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050413 IBM WebSphere Widespread configuration JSP disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111342594129109&w=2"},{"name":"ibm-websphere-information-disclosure(20099)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20099"},{"name":"15501","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/15501"},{"name":"13160","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13160"},{"name":"1013697","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1013697"},{"name":"14962","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14962"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1112","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050413 IBM WebSphere Widespread configuration JSP disclosure","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111342594129109&w=2"},{"name":"ibm-websphere-information-disclosure(20099)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20099"},{"name":"15501","refsource":"OSVDB","url":"http://www.osvdb.org/15501"},{"name":"13160","refsource":"BID","url":"http://www.securityfocus.com/bid/13160"},{"name":"1013697","refsource":"SECTRACK","url":"http://securitytracker.com/id?1013697"},{"name":"14962","refsource":"SECUNIA","url":"http://secunia.com/advisories/14962"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1112","datePublished":"2005-04-16T04:00:00.000Z","dateReserved":"2005-04-16T00:00:00.000Z","dateUpdated":"2024-08-07T21:36:00.228Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"1F4DC6FE-BBB4-45AA-8A5F-F204E798DF07"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"8873A6A6-D840-48E2-AED2-BB8584E3817A"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*","matchCriteriaId":"AB3F05B9-6EE1-4838-AD41-7DD329E71E3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.1:*:*:*:*:*:*:*","matchCriteriaId":"91D25A56-D654-46B2-9437-2AAEE74655B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.3:*:*:*:*:*:*:*","matchCriteriaId":"95BB9B87-8DBB-4FF9-8773-73281C3D52A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.4:*:*:*:*:*:*:*","matchCriteriaId":"37813D54-57C8-4C41-A42D-3C7BBAFA86B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.5:*:*:*:*:*:*:*","matchCriteriaId":"1444794B-F893-44B2-824F-24211B872C4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.6:*:*:*:*:*:*:*","matchCriteriaId":"D3B019F0-A728-4803-B036-14E10A5B0389"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.7:*:*:*:*:*:*:*","matchCriteriaId":"A2E4A501-A198-4462-8813-3D355B5BC212"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.8:*:*:*:*:*:*:*","matchCriteriaId":"AFC0955F-486F-41FF-ACA6-0DF4D966E800"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.0.2.9:*:*:*:*:*:*:*","matchCriteriaId":"F8451E82-F170-4182-A312-70DA75F96983"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*","matchCriteriaId":"66DB2053-6DFD-4FF6-A6E9-444281531E24"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"80A7DAA3-2FFC-4AA3-AEB9-9ADF4A10AC39"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"72DB3E62-C18C-440D-B2C8-E14122D2EEFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.0.5:*:*:*:*:*:*:*","matchCriteriaId":"C6B95B55-7A5E-4504-B5B5-B7B03403E3A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*","matchCriteriaId":"31419896-89F7-43A2-8B7C-3B92744BBC46"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"FDA0FE3E-2FB7-415D-BC64-4B5157EABB21"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.1.2:*:*:*:*:*:*:*","matchCriteriaId":"559355CF-7FA8-4D90-8393-90C912F571C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:5.1.1.3:*:*:*:*:*:*:*","matchCriteriaId":"355967D9-475A-49AF-A3FF-E0AC3668B289"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"01F45BA3-6504-47AF-B757-7B6D3526FBF6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1112","Ordinal":"1","Title":"CVE-2005-1112","CVE":"CVE-2005-1112","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1112","Ordinal":"1","NoteData":"IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.","Type":"Description","Title":"CVE-2005-1112"},{"CveYear":"2005","CveId":"1112","Ordinal":"2","NoteData":"2005-04-16","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1112","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}