Vulnerability Name: | CVE-2000-1238 (CCN-5588) | ||||||||
Assigned: | 2000-11-27 | ||||||||
Published: | 2000-11-27 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. This vulnerability is addressed in the following product releases: BEA Systems Weblogic Server 5.1 SP 7 BEA Systems WebLogic Express 5.1 SP 7 | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CONFIRM Type: Patch ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Source: MITRE Type: CNA CVE-2000-1238 Source: CCN Type: OSVDB ID: 20987 BEA WebLogic Restricted Page Multiple Slash Authorization Bypass Source: BID Type: Patch 5089 Source: CCN Type: BID-5089 BEA Systems WebLogic Access Controls Bypass Vulnerability Source: CCN Type: BID-509 Qbik WinGate Buffer Overflow DoS Vulnerability Source: XF Type: UNKNOWN weblogic-bypass-auth(5588) Source: XF Type: UNKNOWN weblogic-bypass-auth(5588) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |