| Vulnerability Name: | CVE-2007-0417 (CCN-31578) | ||||||||
| Assigned: | 2007-01-16 | ||||||||
| Published: | 2007-01-16 | ||||||||
| Updated: | 2011-03-08 | ||||||||
| Summary: | BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity. | ||||||||
| CVSS v3 Severity: | 8.0 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-0417 Source: BEA Type: Patch, Vendor Advisory BEA07-144.00 Source: OSVDB Type: UNKNOWN 38511 Source: CCN Type: SA23750 BEA WebLogic Multiple Vulnerabilities and Security Issues Source: SECUNIA Type: UNKNOWN 23750 Source: CCN Type: SECTRACK ID: 1017525 WebLogic Bugs Let Remote Users Gain Access, Obtain Information, and Deny Service Source: SECTRACK Type: UNKNOWN 1017525 Source: CCN Type: OSVDB ID: 38511 BEA WebLogic Server Compatibility Realm EJB Container Persistence Privileged Operation Execution Source: BID Type: UNKNOWN 22082 Source: CCN Type: BID-22082 BEA Multiple Products Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-0213 Source: XF Type: UNKNOWN weblogic-ejb-privilege-escalation(31578) Source: CCN Type: BEA07-144.00 Some EJB calls can be unintentionally executed with administrative privileges when using WebLogic Server 6.1 compatibility realm | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||