Unrated severityNVD Advisory· Published Jun 27, 2006· Updated Jun 16, 2026
CVE-2006-3231
CVE-2006-3231
Description
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
Affected products
51cpe:2.3:a:ibm:websphere_application_server:2.0:*:*:*:*:*:*:*+ 50 more
- cpe:2.3:a:ibm:websphere_application_server:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.0.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:3.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.15:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.16:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.0.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:5.1.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:*
- (no CPE)range: <6.0.2.11
Patches
Vulnerability mechanics
References
8- secunia.com/advisories/20732nvdPatchVendor Advisory
- secunia.com/advisories/24478nvdVendor Advisory
- www.vupen.com/english/advisories/2006/2482nvdVendor Advisory
- www.vupen.com/english/advisories/2007/0970nvdVendor Advisory
- www-1.ibm.com/support/docview.wssnvd
- www-1.ibm.com/support/docview.wssnvd
- www.securityfocus.com/bid/18578nvd
- www.securityfocus.com/bid/22991nvd
News mentions
0No linked articles in our index yet.