IBM WebSphere Showcode Vulnerability

BID:1500

Info

IBM WebSphere Showcode Vulnerability

Bugtraq ID: 1500
Class: Access Validation Error
CVE:
Remote: Yes
Local: Yes
Published: Jul 24 2000 12:00AM
Updated: Jul 24 2000 12:00AM
Credit: This advisory was released by Foundstone Inc. who credit Shreeraj Shah ([email protected]) Saumil Shah ([email protected]) with the dicovery. Further, this advisory was posted to the Bugtraq mailing list on July 24, 2000.
Vulnerable: IBM Websphere Application Server 3.0.2 .1
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 3.0
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Novell Netware 5.0
- Sun Solaris 8_sparc
IBM Websphere Application Server 2.0
- IBM AIX 4.3
- Linux kernel 2.3 .x
- Microsoft Windows NT 4.0
- Novell Netware 5.0
- Sun Solaris 8_sparc
Not Vulnerable:

Discussion

IBM WebSphere Showcode Vulnerability

Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

Exploit / POC

IBM WebSphere Showcode Vulnerability

The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

"It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
parsed or compiled. For example if the URL for a file "login.jsp" is:

http://site.running.websphere/login.jsp

then accessing

http://site.running.websphere/servlet/file/login.jsp

would cause the unparsed contents of the file to show up in the web browser."

Solution / Fix

IBM WebSphere Showcode Vulnerability

Solution:
IBM has announced the following fix:


IBM Websphere Application Server 3.0.2 .1

References

© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report