4.6
CVE-2006-0421
- EPSS 0.4%
- Veröffentlicht 25.01.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:20:34
- Erkennungen
By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 6.1
Bea ≫ Weblogic Server Version 6.1 Edition express
Bea ≫ Weblogic Server Version 7.0
Bea ≫ Weblogic Server Version 7.0 Edition express
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.318 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
http://securitytracker.com/id?1015528
http://dev2dev.bea.com/pub/advisory/165
http://secunia.com/advisories/18581
http://www.securityfocus.com/bid/16358
http://www.vupen.com/english/advisories/2006/0313
https://exchange.xforce.ibmcloud.com/vulnerabilities/24286