← Back

CVE-2003-0151

nvd nist
Published: Mar 24, 2003Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.

Affected (28)

Products: Bea: Weblogic Server
1 product
Weblogic Server
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Bea
Version 6.0
Version 6.0
Version 6.0 sp1
Version 6.0 sp1
Version 6.0 sp2
Version 6.0 sp2
Version 6.1
Version 6.1
Version 6.1 sp1
Version 6.1 sp1
Version 6.1 sp2
Version 6.1 sp2
Version 6.1 sp3
Version 6.1 sp3
Version 6.1 sp4
Version 6.1 sp4
Version 7.0.0.1
Version 7.0.0.1
Version 7.0.0.1 sp1
Version 7.0.0.1 sp1
Version 7.0.0.1 sp2
Version 7.0.0.1 sp2
Version 7.0
Version 7.0
Version 7.0 sp1
Version 7.0 sp1
Version 7.0 sp2
Version 7.0 sp2

References (12)

Timeline

No history available yet.