Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0640

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2003-0640
Last Modified 05 Sep 2008 04:34:51
Published 27 Aug 2003 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0640

Summary

BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.

Vulnerable Systems

Application

  • Bea Weblogic Server


References

SECUNIA - 9232

CONFIRM - http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp


Last Updated: 27 May 2016 10:37:59