Affects:
- Java System Web Server 7.0 and prior [Medium]
Description
Sun Java System Web Server (aka Sun ONE Web Server) 6.1, 6.1 SP10, 6.1 SP11, and 7.0 Update 5 on Windows allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.
If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.
CVE Identifier: CVE-2009-2445
Severity: Medium












