Summary
This vulnerability affects the Win32 versions of multiple j2ee servlet containers / application servers. By making a particular request to the servers in question it is possible to retrieve files located under the 'WEB-INF' directory.
For example:
www.someserver.com/WEB-INF./web.xml
or
www.someserver.com/WEB-INF./classes/MyServlet.class
Solution
Contact your vendor for the appropriate patch.
Severity
Classification
-
CVE CVE-2002-1855, CVE-2002-1856, CVE-2002-1857, CVE-2002-1858, CVE-2002-1859, CVE-2002-1860, CVE-2002-1861 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities