Field Assessment
AI analysis pending.
CVE
CVE-2000-1247
Severity
LOW
CVSS
2.1
EPSS
0.58%
Apache
Original Filing — NVD Description
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.