Skip to content

H3-2026-0066

TJWS2 WEB-INF Descriptor Disclosure Vulnerability

Category VULNERABILITY
Base Score 5.3

Description

D. Rogatkin's TJWS2 discloses WEB-INF descriptors to unauthenticated requests via a dot-slash path that bypasses its WEB-INF guard. Public since 2010, no CVE.

Impact

Unauthenticated disclosure of WEB-INF descriptors (web.xml, weblogic.xml) and any secrets they contain.

References