Vulnerability Name: | CVE-2009-1003 (CCN-50054) | ||||||||
Assigned: | 2009-04-14 | ||||||||
Published: | 2009-04-14 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors related to "access to source code of web pages." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1003 Source: OSVDB Type: UNKNOWN 53762 Source: CCN Type: SECTRACK ID: 1022059 Oracle WebLogic Server and Portal Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions Source: CCN Type: Oracle Critical Patch Update Advisory - April 2009 Oracle Critical Patch Update Advisory - April 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2009-1003) Source code disclosure in WebLogic Server web pages Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technology/deploy/security/wls-security/1003.html Source: CCN Type: OSVDB ID: 53762 Oracle BEA WebLogic Server Servlet Container Unspecified Remote Issue (CVE-2009-1003) Source: BID Type: UNKNOWN 34461 Source: CCN Type: BID-34461 Oracle April 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1022059 Source: CERT Type: US Government Resource TA09-105A Source: XF Type: UNKNOWN oracle-weblogic-wls-read-source(50054) Source: XF Type: UNKNOWN oracle-weblogic-wls-read-source(50054) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |