The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1328 | patch vdb entry exploit vendor advisory broken link third party advisory |
http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.htm | broken link mailing list |
http://developer.bea.com/alerts/security_000612.html | broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/4694 | third party advisory vdb entry |