| Vulnerability Name: | CVE-2000-0499 (CCN-4694) | ||||||||
| Assigned: | 2000-06-08 | ||||||||
| Published: | 2000-06-08 | ||||||||
| Updated: | 2017-10-10 | ||||||||
| Summary: | The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Mon Jun 12 2000 - 00:19:45 CDT BEA WebLogic JSP showcode vulnerability Source: NTBUGTRAQ Type: UNKNOWN 20000612 BEA WebLogic JSP showcode vulnerability Source: MITRE Type: CNA CVE-2000-0499 Source: CONFIRM Type: UNKNOWN http://developer.bea.com/alerts/security_000612.html Source: CCN Type: Foundstone Security Advisory FS-061200-2-BEA New BEA WebLogic showcode vulnerability discovered by Foundstone, Inc. Source: CCN Type: OSVDB ID: 7310 BEA WebLogic Upper Case Request JSP Source Disclosure Source: BID Type: Exploit, Patch, Vendor Advisory 1328 Source: CCN Type: BID-1328 Multiple Vendor JSP Source Code Disclosure Vulnerability Source: CCN Type: BEA WebLogic Web site WebLogic Server HTTP Configuration Source: XF Type: UNKNOWN weblogic-jsp-source-read(4694) Source: XF Type: UNKNOWN weblogic-jsp-source-read(4694) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||