AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-4223

MEDIUM · CVSS 5 EPSS 1.36%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-08-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.0. See the original NVD description below for full technical details.

CVE
CVE-2006-4223
Severity
MEDIUM
CVSS
5
EPSS
1.36%

Original NVD Description

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.