7.5

CVE-2002-2142

An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BeaWeblogic Integration Version7.0
BeaWeblogic Integration Version7.0 Updatesp1
BeaWeblogic Server Version6.0
BeaWeblogic Server Version6.0 Editionexpress
BeaWeblogic Server Version6.1
BeaWeblogic Server Version6.1 Editionexpress
BeaWeblogic Server Version7.0
BeaWeblogic Server Version7.0 Editionexpress
BeaWeblogic Server Version7.0.0.1
BeaWeblogic Server Version7.0.0.1 Editionexpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.637
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P