"value":"Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message."
},
{
"lang":"es",
"value":"Apache Axis 1.0 permite a atacantes remotos obtener informaci\u00f3n confidencial al solicitar un fichero WSDL no existente, lo cual revela la ruta de instalaci\u00f3n en el mensaje de excepci\u00f3n resultante."
}
],
"vendorComments":[
{
"organization":"Red Hat",
"comment":"Red Hat ship Axis in a number of products; however the installation path of Axis is fixed and deterministic, so this flaw does not disclose otherwise unknown information. We do not plan on issuing updates to fix this issue.",