2.6
CVE-2002-2177
- EPSS 1.23%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:00:47
- Erkennungen
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 6.1
Bea ≫ Weblogic Server Version 6.1 Edition express
Bea ≫ Weblogic Server Version 6.1 Update sp1
Bea ≫ Weblogic Server Version 6.1 Update sp1 Edition express
Bea ≫ Weblogic Server Version 7.0
Bea ≫ Weblogic Server Version 7.0 Edition express
Bea ≫ Weblogic Server Version 7.0.0.1
Bea ≫ Weblogic Server Version 7.0.0.1 Edition express
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.23% | 0.651 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:P/I:N/A:N
|
http://dev2dev.bea.com/pub/advisory/38
http://www.iss.net/security_center/static/10221.php
http://www.securityfocus.com/bid/5819