BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters…
提示
摘要
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588
时间线
- nvd_ingest NVD