VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-6285
http://www.vmware.com/security/advisories/VMSA-2016-0021.html