2.1
CVE-2004-0471
- EPSS 0.4%
- Veröffentlicht 07.07.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:41
- Erkennungen
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 7.0
Bea ≫ Weblogic Server Version 7.0 Edition express
Bea ≫ Weblogic Server Version 8.1
Bea ≫ Weblogic Server Version 8.1 Edition express
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.316 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp
http://secunia.com/advisories/11594
http://securitytracker.com/id?1010129
http://www.osvdb.org/6077
http://www.securityfocus.com/bid/10327
https://exchange.xforce.ibmcloud.com/vulnerabilities/16121