6

CVE-2008-0900

Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.

Data is provided by the National Vulnerability Database (NVD)
BeaWeblogic Server Version8.1 Updatesp4
BeaWeblogic Server Version8.1 Updatesp4 Editionexpress
BeaWeblogic Server Version8.1 Updatesp5
BeaWeblogic Server Version8.1 Updatesp5 Editionexpress
BeaWeblogic Server Version8.1 Updatesp6
BeaWeblogic Server Version8.1 Updatesp6 Editionexpress
BeaWeblogic Server Version9.2
BeaWeblogic Server Version9.2 Updatemp1
BeaWeblogic Server Version10.0
Bea SystemsWeblogic Express Version9.2 Updatemp1
Bea SystemsWeblogic Express Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.53% 0.887
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P