Vulnerabilities > CVE-2007-2699 - File-Upload vulnerability in Weblogic Server 9.0/9.1

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
bea

Summary

The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Bea
4

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153072/oats_weblogic_console.rb.txt
idPACKETSTORM:153072
last seen2019-05-29
published2019-05-24
reportermr_me
sourcehttps://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html
titleOracle Application Testing Suite WebLogic Server Administration Console War Deployment