CVE-2006-7164
Last modified
CVE-2006-7164 is a vulnerability of currently unknown severity. SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Application Server | 5.0.1 |
| Ibm | Websphere Application Server | 5.0.2 |
| Ibm | Websphere Application Server | 5.0.2.1 |
| Ibm | Websphere Application Server | 5.0.2.2 |
| Ibm | Websphere Application Server | 5.0.2.3 |
| Ibm | Websphere Application Server | 5.0.2.4 |
| Ibm | Websphere Application Server | 5.0.2.5 |
| Ibm | Websphere Application Server | 5.0.2.6 |
| Ibm | Websphere Application Server | 5.0.2.7 |
| Ibm | Websphere Application Server | 5.0.2.8 |
| Ibm | Websphere Application Server | 5.0.2.9 |
| Ibm | Websphere Application Server | 5.0.2.10 |
| Ibm | Websphere Application Server | 5.0.2.11 |
| Ibm | Websphere Application Server | 5.0.2.12 |
| Ibm | Websphere Application Server | 5.0.2.13 |
| Ibm | Websphere Application Server | 5.0.2.14 |
| Ibm | Websphere Application Server | 5.0.2.15 |
| Ibm | Websphere Application Server | 5.0.2.16 |
References
- http://www-1.ibm.com/support/docview.wss?uid=swg24013029Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24013029Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-7164?
How severe is CVE-2006-7164?
How do I fix CVE-2006-7164?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-7158Cross-site scripting (XSS) vulnerability in Oracle Applicati…
- CVE-2006-7159Directory traversal vulnerability in include/prune_torrents.…
- CVE-2006-7160The Sandbox.sys driver in Outpost Firewall PRO 4.0, and poss…
- CVE-2006-7161SQL injection vulnerability in giris_yap.asp in Hazir Site 2…
- CVE-2006-7162PuTTY 0.59 and earlier uses weak file permissions for (1) pp…
- CVE-2006-7163DreameeSoft Password Master 1.0 stores the database in an un…
- CVE-2006-7165IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 a…
- CVE-2006-7166IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier a…
- CVE-2006-7167Unspecified vulnerability in ProRat Server 1.9 Fix2 allows r…
- CVE-2006-7168PHP remote file inclusion vulnerability in includes/not_mem.…
- CVE-2006-7169PHP remote file inclusion vulnerability in includes/header_s…
- CVE-2006-7170Multiple SQL injection vulnerabilities in Koan Software Mega…
Are you affected by CVE-2006-7164?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
