PT-2000-1437 · Bea · Bea Weblogic

Published

2000-06-08

·

Updated

2024-01-26

·

CVE-2000-0499

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic versions 3.1.8 through 4.5.1
Description The default configuration of the software allows a remote attacker to view the source code of a JSP program. This can be achieved by requesting a URL that provides the JSP extension in upper case.
Recommendations For BEA WebLogic versions 3.1.8 through 4.5.1, consider changing the default configuration to prevent remote attackers from viewing the source code of JSP programs. As a temporary workaround, restrict access to JSP files to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2000-0499

Affected Products

Bea Weblogic