7.5
CVE-2002-2141
- EPSS 2.36%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:43
- Erkennungen
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 7.0
Bea ≫ Weblogic Server Version 7.0 Edition express
Bea ≫ Weblogic Server Version 7.0.0.1
Bea ≫ Weblogic Server Version 7.0.0.1 Edition express
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.36% | 0.816 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://dev2dev.bea.com/pub/advisory/39
http://www.iss.net/security_center/static/10291.php
http://www.securityfocus.com/bid/5846