CVE-2003-0151
Summary
| CVE | CVE-2003-0151 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-03-24 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Server | 6.0 | All | All | All |
| Application | Bea | Weblogic Server | 6.0 | All | express | All |
| Application | Bea | Weblogic Server | 6.0 | sp1 | All | All |
| Application | Bea | Weblogic Server | 6.0 | sp1 | express | All |
| Application | Bea | Weblogic Server | 6.0 | sp2 | All | All |
| Application | Bea | Weblogic Server | 6.0 | sp2 | express | All |
| Application | Bea | Weblogic Server | 6.1 | All | All | All |
| Application | Bea | Weblogic Server | 6.1 | All | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp3 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp3 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp4 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp4 | express | All |
| Application | Bea | Weblogic Server | 7.0 | All | All | All |
| Application | Bea | Weblogic Server | 7.0 | All | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | All | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | All | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp2 | express | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories & Notifications | af854a3a-2127-422b-91ae-364da2661108 | dev2dev.bea.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| BEA WebLogic Internal Servlet Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Page not found – S21Sec | af854a3a-2127-422b-91ae-364da2661108 | www.s21sec.com | |
| 'S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| BEA WebLogic Remote Unprivileged Administration Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.