7.5

CVE-2000-1238

BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.

Data is provided by the National Vulnerability Database (NVD)
BeaWeblogic Server Version5.1
BeaWeblogic Server Version5.1 Editionexpress
BeaWeblogic Server Version5.1 Updatesp1
BeaWeblogic Server Version5.1 Updatesp1 Editionexpress
BeaWeblogic Server Version5.1 Updatesp2
BeaWeblogic Server Version5.1 Updatesp2 Editionexpress
BeaWeblogic Server Version5.1 Updatesp3
BeaWeblogic Server Version5.1 Updatesp3 Editionexpress
BeaWeblogic Server Version5.1 Updatesp4
BeaWeblogic Server Version5.1 Updatesp4 Editionexpress
BeaWeblogic Server Version5.1 Updatesp5
BeaWeblogic Server Version5.1 Updatesp5 Editionexpress
BeaWeblogic Server Version5.1 Updatesp6
BeaWeblogic Server Version5.1 Updatesp6 Editionexpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.6% 0.67
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P