7.5

CVE-2003-0151

BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BeaWeblogic Server Version6.0
BeaWeblogic Server Version6.0 Editionexpress
BeaWeblogic Server Version6.0 Updatesp1
BeaWeblogic Server Version6.0 Updatesp1 Editionexpress
BeaWeblogic Server Version6.0 Updatesp2
BeaWeblogic Server Version6.0 Updatesp2 Editionexpress
BeaWeblogic Server Version6.1
BeaWeblogic Server Version6.1 Editionexpress
BeaWeblogic Server Version6.1 Updatesp1
BeaWeblogic Server Version6.1 Updatesp1 Editionexpress
BeaWeblogic Server Version6.1 Updatesp2
BeaWeblogic Server Version6.1 Updatesp2 Editionexpress
BeaWeblogic Server Version6.1 Updatesp3
BeaWeblogic Server Version6.1 Updatesp3 Editionexpress
BeaWeblogic Server Version6.1 Updatesp4
BeaWeblogic Server Version6.1 Updatesp4 Editionexpress
BeaWeblogic Server Version7.0
BeaWeblogic Server Version7.0 Editionexpress
BeaWeblogic Server Version7.0 Updatesp1
BeaWeblogic Server Version7.0 Updatesp1 Editionexpress
BeaWeblogic Server Version7.0 Updatesp2
BeaWeblogic Server Version7.0 Updatesp2 Editionexpress
BeaWeblogic Server Version7.0.0.1
BeaWeblogic Server Version7.0.0.1 Editionexpress
BeaWeblogic Server Version7.0.0.1 Updatesp1
BeaWeblogic Server Version7.0.0.1 Updatesp1 Editionexpress
BeaWeblogic Server Version7.0.0.1 Updatesp2
BeaWeblogic Server Version7.0.0.1 Updatesp2 Editionexpress
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.73% 0.89
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P