Back

CVE-2005-0425

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
ibm websphere_application_server 5.0
ibm websphere_application_server 5.1.0
ibm websphere_application_server 6.0

GitHub Security Advisory GHSA-hxxg-433j-m5fg

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.10%

Top 20% most likely to be exploited

Threat Score 20.6 / 100

Data Sources

NVD EPSS GitHub