IBM WebSphere Application Server '%20' Request Source Disclosure

medium Nessus Plugin ID 23638

Synopsis

The remote web server is affected by an information disclosure flaw.

Description

It is possible to make the remote web server disclose the source code of its JSP pages by requesting the .jsp file with a '%20' appended to the request.

An attacker may use this flaw to get the source code of your CGIs and possibly to obtain passwords and other relevant information about this host.

Solution

Apply version 6.1.0 Fix Pack 2 or later.

See Also

http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg24013142

Plugin Details

Severity: Medium

ID: 23638

File Name: websphere_jsp_source2.nasl

Version: 1.19

Type: remote

Family: CGI abuses

Published: 11/14/2006

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:ibm:websphere_application_server

Required KB Items: www/WebSphere

Exploit Ease: No exploit is required

Patch Publication Date: 9/8/2006

Vulnerability Publication Date: 2/11/2005

Reference Information

CVE: CVE-2005-0425

BID: 20455