High

CVE-2003-0151 - Unspecified vulnerability in BEA Weblogic Server

Publication: 2003-03-24
Summary

BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.

Risk level (CVSS 7.5)

High

7.5

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.0
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 6.1
  • BEA Weblogic Server 7.0.0.1
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0
  • BEA Weblogic Server 7.0.0.1
  • BEA Weblogic Server 7.0.0.1
  • BEA Weblogic Server 7.0.0.1
  • BEA Weblogic Server 7.0.0.1
  • BEA Weblogic Server 7.0.0.1