| Vulnerability Name: | CVE-2000-0685 (CCN-5027) | ||||||||
| Assigned: | 2000-08-01 | ||||||||
| Published: | 2000-08-01 | ||||||||
| Updated: | 2008-09-10 | ||||||||
| Summary: | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.8 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: BUGTRAQ Type: Patch, Vendor Advisory 20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution Source: CCN Type: BugTraq Mailing List, Mon Jul 31 2000 - 11:53:02 CDT BEA's WebLogic *.jsp/*.jhtml remote command execution Source: MITRE Type: CNA CVE-2000-0684 Source: MITRE Type: CNA CVE-2000-0685 Source: CCN Type: BEA Systems, Inc. Security Advisory BEA00-04.00 Compilation and execution of arbitrary files in web document root directory Source: CONFIRM Type: UNKNOWN http://developer.bea.com/alerts/security_000731.html Source: CCN Type: CERT Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests Source: CCN Type: Foundstone Security Advisory FS-073100-10-BEA BEA WebLogic remote commmand execution vulnerability discovered by Foundstone, Inc. Source: CCN Type: OSVDB ID: 1483 BEA WebLogic JSPServlet Remote Code Execution Source: CCN Type: OSVDB ID: 59351 BEA WebLogic PageCompileServlet jsp / jhtml Arbitrary Command Execution Source: BID Type: Exploit, Patch, Vendor Advisory 1525 Source: CCN Type: BID-1525 Weblogic Remote Command Execution Vulnerability Source: XF Type: UNKNOWN weblogic-java-injection(5027) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||