CVE-2003-1095

BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:sp1:win32:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:win32:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:win32:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-27.jsp - () http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-27.jsp -
References () http://www.kb.cert.org/vuls/id/691153 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/691153 - Patch, Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/7130 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/7130 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/11555 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/11555 -

Information

Published : 2003-03-18 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1095

Mitre link : CVE-2003-1095

CVE.ORG link : CVE-2003-1095


JSON object : View

Products Affected

bea

  • weblogic_server