Back
CVE-2005-0425
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 5.0 |
| ibm | websphere_application_server | 5.1.0 |
| ibm | websphere_application_server | 6.0 |
GitHub Security Advisory GHSA-hxxg-433j-m5fg
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on...
References (6)
- http://secunia.com/advisories/14274 Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008814 Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008815 Patch, Vendor Advisory
- http://secunia.com/advisories/14274 Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008814 Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008815 Patch, Vendor Advisory
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
2.10%
Top 20% most likely to be exploited
Threat Score
20.6 / 100
Data Sources
NVD
EPSS
GitHub