Skip to content

H3-2026-0067

Exposed Java WEB-INF Deployment Descriptor Vulnerability

Category SECURITY_MISCONFIGURATION
Base Score 5.3

Description

A Java web application's WEB-INF/web.xml deployment descriptor is directly retrievable over HTTP.

Impact

Discloses servlet mappings, parameters, and sometimes embedded credentials or datasource configuration.

References