CVE-2000-1238
טרם דורגה
תיאור (מקור, אנגלית)
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
מדדים
- EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-23/9/2026
מוצרים מושפעים
bea: weblogic server
קישורים
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip Patch
- http://www.securityfocus.com/bid/5089 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5588