CVE-2000-0684
Summary
| CVE | CVE-2000-0684 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2000-10-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Server | 3.1.8 | All | All | All |
| Application | Bea | Weblogic Server | 4.0.4 | All | All | All |
| Application | Bea | Weblogic Server | 4.5.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Weblogic Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| archives.neohapsis.com/archives/bugtraq/2000-07/0434.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Patch, Vendor Advisory |
| BEA Systems Developer Center ~ Advisory BEA00-04.00 | af854a3a-2127-422b-91ae-364da2661108 | developer.bea.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.