IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
BID:12537
Info
IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
| Bugtraq ID: | 12537 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2005 12:00AM |
| Updated: | Feb 14 2005 12:00AM |
| Credit: | This issue was reported by IBM. |
| Vulnerable: |
IBM Websphere Application Server 5.1.1 .3 IBM Websphere Application Server 5.1.1 .2 IBM Websphere Application Server 5.1.1 .1 IBM Websphere Application Server 5.1 .0.5 IBM Websphere Application Server 5.1 .0.4 IBM Websphere Application Server 5.1 .0.3 IBM Websphere Application Server 5.1 .0.2 IBM Websphere Application Server 5.0.2 .9 IBM Websphere Application Server 5.0.2 .8 IBM Websphere Application Server 5.0.2 .7 IBM Websphere Application Server 5.0.2 .6 IBM Websphere Application Server 5.0.2 .5 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
IBM WebSphere Application Server is prone to a source code disclosure vulnerability. An attacker can exploit this issue by supplying a malformed URI to the server to disclose JSP source code.
It should be noted that this issue only affects WebSphere Application Server versions 5.0 and 5.1 running on Microsoft Windows platforms.
IBM WebSphere Application Server is prone to a source code disclosure vulnerability. An attacker can exploit this issue by supplying a malformed URI to the server to disclose JSP source code.
It should be noted that this issue only affects WebSphere Application Server versions 5.0 and 5.1 running on Microsoft Windows platforms.
Exploit / POC
IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
An exploit is not required to leverage this issue.
An exploit is not required to leverage this issue.
Solution / Fix
IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
Solution:
IBM has released fixes to address this issue for versions 5.0.2.9, 5.1.0.5, and 5.1.1.3.
IBM Websphere Application Server 5.0.2 .9
IBM Websphere Application Server 5.1 .0.5
IBM Websphere Application Server 5.1.1 .3
Solution:
IBM has released fixes to address this issue for versions 5.0.2.9, 5.1.0.5, and 5.1.1.3.
IBM Websphere Application Server 5.0.2 .9
-
IBM PQ99537
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PQ 99537/PQ99537_fix.jar
IBM Websphere Application Server 5.1 .0.5
-
IBM PQ99537
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PQ 99537/PQ99537_fix.jar
IBM Websphere Application Server 5.1.1 .3
References
IBM WebSphere Application Server JSP Engine Source Code Disclosure Vulnerability
References:
References: