BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters…
Info
Summary
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588
Timeline
- nvd_ingest NVD