Symptom
- Visiting the following URLs displays the credentials for axis2 logon service in plain text.
- http://<hostname>:8080/dswsbobje/services/Session?xsd=..\\conf\axis2.xml
- https://<hostname>/dswsbobje/services/Session?xsd=..\\conf\axis2.xml
Read more...
Environment
- SAP Business Objects XI Release 3.1 Service Pack 2
- Web Application server: Tomcat 5
Product
SAP BusinessObjects Business Intelligence platform R2
Keywords
axis2 directory traversal, directory traversal , KBA , BI-BIP-DEP , Webapp Deployment, Networking, Vulnerabilities, Webservices , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.