J-Security Center

Title: Multiple Vendor JSP Source Code Disclosure Vulnerability

Severity: MODERATE

Description:

Many webservers are case-sensitive, but do not have all possible combinations of cases in mapped extensions mapped properly.

By changing the letters in a JSP or a JHTML file extension from lower case to upper case (eg: .jsp or .jhtml becomes .JSP or .JHTML) in a URL the server does not recognize the file extension and sends the file normally. In that manner, a user is able to access the source code to those specific files.

Affected Products:

  • BEA Systems WebLogic Express 3.1.8
  • BEA Systems Weblogic 3.1.8
  • BEA Systems Weblogic 4.0.4
  • BEA Systems Weblogic Server 4.5.1
  • IBM Websphere Application Server 3.0.2.1
  • Unify eWave ServletExec 3.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.