IBM WebSphere Application 6 and prior are vulnerable to a JSP sourcecode disclosure issue when the Application Server and Webserver roots are configured to be the same.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/37215/ibm_websphere_jsp_src.txt
Source: https://packetstormsecurity.com/files/37215/ibm_websphere_jsp_src.txt.html