Filtered by vendor Apache Subscriptions
Filtered by product Jserv Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2000-1247 1 Apache 1 Jserv 2024-11-21 N/A
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.