Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.398
EPSS Ranking 97.2%