PT-2007-4016 · Bea · Bea Weblogic Server+1
Publicado
2007-05-16
·
Atualizado
2019-05-28
·
CVE-2007-2699
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 9.0 through 9.1
BEA WebLogic Express versions 9.0 through 9.1
Description
The issue is related to the Administration Console in the affected software, which fails to properly enforce certain Domain Security Policies. This allows remote administrative users in the Deployer role to upload arbitrary files.
Recommendations
For BEA WebLogic Server versions 9.0 through 9.1, restrict access to the Administration Console to minimize the risk of exploitation.
For BEA WebLogic Express versions 9.0 through 9.1, consider disabling file upload functionality for the Deployer role until a fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bea Weblogic Express
Bea Weblogic Server