← Back

CVE-2000-0684

nvd nist
Published: Oct 20, 2000Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.

Affected (3)

Products: Bea: Weblogic Server
1 product
Weblogic Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Bea
Version 3.1.8
Version 4.0.4
Version 4.5.1

References (6)

Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.