CVE-2003-1094

BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp - () http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp -
References () http://www.kb.cert.org/vuls/id/999788 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/999788 - Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/8320 - Patch () http://www.securityfocus.com/bid/8320 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/12799 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/12799 -

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1094

Mitre link : CVE-2003-1094

CVE.ORG link : CVE-2003-1094


JSON object : View

Products Affected

bea

  • weblogic_server