Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
https://exchange.xforce.ibmcloud.com/vulnerabilities/14921
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2096
http://www.securityfocus.com/bid/9479