Description
The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stealth Login Page Unspecified Vulnerability (1.1.3)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3628)
Joomla! Core 3.9.x Directory Traversal (3.9.3 - 3.9.5)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.2.1)