It was found that the InterfaceGenerator handler in JBoss Seam Remoting will expose details of all classes and methods on the server's classpath, not just methods with the org.jboss.seam.annotations.remoting.WebRemote annotation. A remote attacker could use this flaw to determine which classes are deployed on the JBoss server.