Description
An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.
References
www.bessystem.com/appserver/dtds/bes-web-app_2_5-0.dtd
www.bessystem.com/...b8c4d6af462b8d15723a5f25a87d/info?p=101
gist.github.com/Liu2000622/7a6294f7421ef50c378a456ca9494714