| Vulnerability Name: | CVE-2008-0899 (CCN-40696) | ||||||||
| Assigned: | 2008-02-19 | ||||||||
| Published: | 2008-02-19 | ||||||||
| Updated: | 2011-03-08 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-0899 Source: BEA Type: Patch BEA08-195.00 Source: CCN Type: SA29041 BEA WebLogic Products Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 29041 Source: CCN Type: SECTRACK ID: 1019448 WebLogic Server Administration Console Input Validation Hole Permits Cross-Site Scripting Attacks Source: CCN Type: OSVDB ID: 41893 BEA WebLogic Consoleâs Unexpected Exception Page XSS Source: CCN Type: BID-27893 BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1019448 Source: VUPEN Type: UNKNOWN ADV-2008-0612 Source: XF Type: UNKNOWN bea-weblogic-administration-console-xss(40696) Source: CCN Type: BEA08-195.00 Cross-site scripting vulnerability in Consoles Unexpected Exception Page | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||