Vulnerability Name: | CCN-11253 | ||||||
Published: | 2002-04-30 | ||||||
Updated: | 2002-04-30 | ||||||
Summary: | BEA WebLogic Server and Express could allow a local attacker to gain "system" user privileges. The "system" user is the default privileged user for managing the WebLogic Server. By creating a custom file containing malicious code and installing it on the system as part of a compressed jar, war, rar, or ear file, a local attacker could execute the malicious code on the system to gain "system" user privileges. | ||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: XF Type: UNKNOWN weblogic-file-system-privileges(11253) Source: CCN Type: BEA Systems, Inc. Security Advisory (BEA02-13.00) Patch available for unintended permissions | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |