H3-2026-0066¶
TJWS2 WEB-INF Descriptor Disclosure Vulnerability
| Category | VULNERABILITY |
| Base Score | 5.3 |
Description¶
D. Rogatkin's TJWS2 discloses WEB-INF descriptors to unauthenticated requests via a dot-slash path that bypasses its WEB-INF guard. Public since 2010, no CVE.
Impact¶
Unauthenticated disclosure of WEB-INF descriptors (web.xml, weblogic.xml) and any secrets they contain.