Vulnerability Details CVE-2006-7164
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2006-7164
-
cpe:2.3:a:ibm:websphere_application_server:5.0.1
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.1
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.10
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.11
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.12
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.13
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.14
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.15
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.16
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.2
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.3
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.4
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.5
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.6
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.7
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.8
-
cpe:2.3:a:ibm:websphere_application_server:5.0.2.9
-
cpe:2.3:o:linux:linux_kernel:*
-