{"api_version":"1","generated_at":"2026-07-23T10:56:39+00:00","cve":"CVE-2006-0421","urls":{"html":"https://cve.report/CVE-2006-0421","api":"https://cve.report/api/cve/CVE-2006-0421.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0421","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0421"},"summary":{"title":"CVE-2006-0421","description":"By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-25 23:07:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24286","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0313","name":"http://www.vupen.com/english/advisories/2006/0313","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015528","name":"http://securitytracker.com/id?1015528","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - BEA WebLogic Multiple Bugs Let Remote Users Deny Service, Obtain Information, and Access Restricted Resources","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dev2dev.bea.com/pub/advisory/165","name":"http://dev2dev.bea.com/pub/advisory/165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Oracle Fusion Middleware Technologies","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16358","name":"http://www.securityfocus.com/bid/16358","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BEA WebLogic Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/18581","name":"http://secunia.com/advisories/18581","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"BEA WebLogic Server/Express Multiple Domains Administrator Access - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0421","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0421","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"6.1","cpe7":"*","cpe8":"express","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"7.0","cpe7":"*","cpe8":"express","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"421","cve":"CVE-2006-0421","epss":"0.000930000","percentile":"0.260050000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:34:14.660Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-0313","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0313"},{"name":"BEA06-108.00","tags":["vendor-advisory","x_refsource_BEA","x_transferred"],"url":"http://dev2dev.bea.com/pub/advisory/165"},{"name":"weblogic-cross-domain-management(24286)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24286"},{"name":"1015528","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015528"},{"name":"18581","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18581"},{"name":"16358","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16358"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-0313","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0313"},{"name":"BEA06-108.00","tags":["vendor-advisory","x_refsource_BEA"],"url":"http://dev2dev.bea.com/pub/advisory/165"},{"name":"weblogic-cross-domain-management(24286)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24286"},{"name":"1015528","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015528"},{"name":"18581","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18581"},{"name":"16358","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16358"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0421","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-0313","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0313"},{"name":"BEA06-108.00","refsource":"BEA","url":"http://dev2dev.bea.com/pub/advisory/165"},{"name":"weblogic-cross-domain-management(24286)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24286"},{"name":"1015528","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015528"},{"name":"18581","refsource":"SECUNIA","url":"http://secunia.com/advisories/18581"},{"name":"16358","refsource":"BID","url":"http://www.securityfocus.com/bid/16358"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0421","datePublished":"2006-01-25T23:00:00.000Z","dateReserved":"2006-01-25T00:00:00.000Z","dateUpdated":"2024-08-07T16:34:14.660Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-25 23:07:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*","matchCriteriaId":"1FDCF6AE-43DC-4AE5-9260-CA657F40BE77"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:6.1:*:express:*:*:*:*:*","matchCriteriaId":"05AFBE78-C611-4EA2-8B00-5F8B61696CBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*","matchCriteriaId":"F9C5AFCF-79D8-4005-B800-B0C6BD461276"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*","matchCriteriaId":"FBDF3AC0-0680-4EEE-898C-47D194667BE2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"421","Ordinal":"1","Title":"CVE-2006-0421","CVE":"CVE-2006-0421","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"421","Ordinal":"1","NoteData":"By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.","Type":"Description","Title":"CVE-2006-0421"},{"CveYear":"2006","CveId":"421","Ordinal":"2","NoteData":"2006-01-25","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"421","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}