The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-03-16T19:00:00
Updated: 2024-08-07T04:40:03.756Z
Reserved: 2009-02-10T00:00:00
Link: CVE-2009-0508
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-03-16T19:30:00.467
Modified: 2024-11-21T01:00:04.617
Link: CVE-2009-0508
Redhat
No data.