{"api_version":"1","generated_at":"2026-07-23T03:47:32+00:00","cve":"CVE-2003-1094","urls":{"html":"https://cve.report/CVE-2003-1094","api":"https://cve.report/api/cve/CVE-2003-1094.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1094","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1094"},"summary":{"title":"CVE-2003-1094","description":"BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12799","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp","name":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Fusion Middleware Technologies","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"http://www.kb.cert.org/vuls/id/999788","name":"http://www.kb.cert.org/vuls/id/999788","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#999788","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8320","name":"http://www.securityfocus.com/bid/8320","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"BEA WebLogic Server and WebLogic Express User Impersonation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1094","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1094","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1094","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"7.0","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1094","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"7.0","cpe7":"sp3","cpe8":"express","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1094","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"7.0","cpe7":"sp3","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:12:36.092Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"8320","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8320"},{"name":"weblogic-gain-privileges(12799)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12799"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp"},{"name":"VU#999788","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/999788"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-07-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"8320","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8320"},{"name":"weblogic-gain-privileges(12799)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12799"},{"tags":["x_refsource_CONFIRM"],"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp"},{"name":"VU#999788","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/999788"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1094","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"8320","refsource":"BID","url":"http://www.securityfocus.com/bid/8320"},{"name":"weblogic-gain-privileges(12799)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12799"},{"name":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp","refsource":"CONFIRM","url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp"},{"name":"VU#999788","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/999788"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1094","datePublished":"2005-03-10T05:00:00.000Z","dateReserved":"2005-03-10T00:00:00.000Z","dateUpdated":"2024-08-08T02:12:36.092Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*","matchCriteriaId":"893D9D88-43C4-4F9F-A364-0585DE6FA9E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*","matchCriteriaId":"D59F9859-7344-43F0-9348-E57FABB9E431"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*","matchCriteriaId":"D2D05BAB-AB3B-466E-8301-01A41644DE77"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1094","Ordinal":"1","Title":"CVE-2003-1094","CVE":"CVE-2003-1094","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1094","Ordinal":"1","NoteData":"BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.","Type":"Description","Title":"CVE-2003-1094"},{"CveYear":"2003","CveId":"1094","Ordinal":"2","NoteData":"2005-03-10","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1094","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}