Jakarta Tomcat 3.x/4.0 - Error Message Information Disclosure

EDB-ID:

21073

CVE:



Author:

LoWNOISE

Type:

local


Platform:

Unix

Date:

2001-08-16


source: https://www.securityfocus.com/bid/3199/info

When a malformed request is made for a Java Server Page the server displays an error page. The error page contains potentially sensitive information, along with the absolute path of the JSP file on the webserver, which may aid in further attacks.

Jakarta Tomcat can be configured to display an alternate error file. By default it is not. 

http://webserver.com/\java.jsp