An issue has been discovered in BEA WebLogic Server and Express, which could disclose file contents to unauthorized users. The flaw results due to a non-registered WebLogic servlet. Submitting a specially crafted HTTP request could disclose files residing on the host. Exploitation of this issue could lead to the disclosure of sensitive data which may assist in further attacks against the host.
An issue has been discovered in BEA WebLogic Server and Express, which could disclose file contents to unauthorized users. The flaw results due to a non-registered WebLogic servlet. Submitting a specially crafted HTTP request could disclose files residing on the host. Exploitation of this issue could lead to the disclosure of sensitive data which may assist in further attacks against the host.