6.4
CVE-2004-0713
- EPSS 0.62%
- Published 27.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.
Data is provided by the National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version6.1
Bea ≫ Weblogic Server Version6.1 Editionexpress
Bea ≫ Weblogic Server Version6.1 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp1
Bea ≫ Weblogic Server Version6.1 Updatesp1 Editionexpress
Bea ≫ Weblogic Server Version6.1 Updatesp1 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp2
Bea ≫ Weblogic Server Version6.1 Updatesp2 Editionexpress
Bea ≫ Weblogic Server Version6.1 Updatesp2 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp3
Bea ≫ Weblogic Server Version6.1 Updatesp3 Editionexpress
Bea ≫ Weblogic Server Version6.1 Updatesp3 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp4
Bea ≫ Weblogic Server Version6.1 Updatesp4 Editionexpress
Bea ≫ Weblogic Server Version6.1 Updatesp4 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp5
Bea ≫ Weblogic Server Version6.1 Updatesp5 Editionexpress
Bea ≫ Weblogic Server Version6.1 Updatesp5 Editionwin32
Bea ≫ Weblogic Server Version6.1 Updatesp6
Bea ≫ Weblogic Server Version6.1 Updatesp6 Editionwin32
Bea ≫ Weblogic Server Version7.0
Bea ≫ Weblogic Server Version7.0 Editionexpress
Bea ≫ Weblogic Server Version7.0 Editionwin32
Bea ≫ Weblogic Server Version7.0 Updatesp1
Bea ≫ Weblogic Server Version7.0 Updatesp1 Editionexpress
Bea ≫ Weblogic Server Version7.0 Updatesp1 Editionwin32
Bea ≫ Weblogic Server Version7.0 Updatesp2
Bea ≫ Weblogic Server Version7.0 Updatesp2 Editionexpress
Bea ≫ Weblogic Server Version7.0 Updatesp2 Editionwin32
Bea ≫ Weblogic Server Version7.0 Updatesp3
Bea ≫ Weblogic Server Version7.0 Updatesp3 Editionexpress
Bea ≫ Weblogic Server Version7.0 Updatesp3 Editionwin32
Bea ≫ Weblogic Server Version7.0 Updatesp4
Bea ≫ Weblogic Server Version7.0 Updatesp4 Editionexpress
Bea ≫ Weblogic Server Version7.0 Updatesp4 Editionwin32
Bea ≫ Weblogic Server Version8.1
Bea ≫ Weblogic Server Version8.1 Editionexpress
Bea ≫ Weblogic Server Version8.1 Editionwin32
Bea ≫ Weblogic Server Version8.1 Updatesp1
Bea ≫ Weblogic Server Version8.1 Updatesp1 Editionexpress
Bea ≫ Weblogic Server Version8.1 Updatesp1 Editionwin32
Bea ≫ Weblogic Server Version8.1 Updatesp2
Bea ≫ Weblogic Server Version8.1 Updatesp2 Editionexpress
Bea ≫ Weblogic Server Version8.1 Updatesp2 Editionwin32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.62% | 0.676 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|