{"api_version":"1","generated_at":"2026-07-23T04:06:04+00:00","cve":"CVE-2005-4833","urls":{"html":"https://cve.report/CVE-2005-4833","api":"https://cve.report/api/cve/CVE-2005-4833.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4833","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4833"},"summary":{"title":"CVE-2005-4833","description":"IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via \"a specific JSP URL,\" related to lack of normalization of the URL format.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/0970","name":"http://www.vupen.com/english/advisories/2007/0970","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541","name":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Possible security exposure with JavaServer Page (JSP) and IBM WebSphere Application Server (PK23475, PK32374, PK22928, PK00091, PQ91033, PQ99537, PK28963, PK20181, PK23670) - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg24008815","name":"http://www-1.ibm.com/support/docview.wss?uid=swg24008815","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://osvdb.org/34177","name":"http://osvdb.org/34177","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/22991","name":"http://www.securityfocus.com/bid/22991","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server Source Code Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/24478","name":"http://secunia.com/advisories/24478","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WebSphere Application Server JSP Source Code Disclosure - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4833","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4833","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4833","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:01:23.327Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-0970","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0970"},{"name":"24478","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24478"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541"},{"name":"34177","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/34177"},{"name":"22991","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22991"},{"name":"PK00091","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg24008815"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-02-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via \"a specific JSP URL,\" related to lack of normalization of the URL format."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-13T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-0970","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0970"},{"name":"24478","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24478"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541"},{"name":"34177","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/34177"},{"name":"22991","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22991"},{"name":"PK00091","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg24008815"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4833","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via \"a specific JSP URL,\" related to lack of normalization of the URL format."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-0970","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0970"},{"name":"24478","refsource":"SECUNIA","url":"http://secunia.com/advisories/24478"},{"name":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=swg21243541"},{"name":"34177","refsource":"OSVDB","url":"http://osvdb.org/34177"},{"name":"22991","refsource":"BID","url":"http://www.securityfocus.com/bid/22991"},{"name":"PK00091","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg24008815"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4833","datePublished":"2007-03-20T10:00:00.000Z","dateReserved":"2007-03-20T00:00:00.000Z","dateUpdated":"2024-08-08T00:01:23.327Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"01F45BA3-6504-47AF-B757-7B6D3526FBF6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4833","Ordinal":"1","Title":"CVE-2005-4833","CVE":"CVE-2005-4833","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4833","Ordinal":"1","NoteData":"IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via \"a specific JSP URL,\" related to lack of normalization of the URL format.","Type":"Description","Title":"CVE-2005-4833"},{"CveYear":"2005","CveId":"4833","Ordinal":"2","NoteData":"2007-03-20","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4833","Ordinal":"3","NoteData":"2008-11-13","Type":"Other","Title":"Modified"}]}}}