Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
https://exchange.xforce.ibmcloud.com/vulnerabilities/34167
https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-2348