PT-2000-1618 · Bea · Bea Weblogic
Published
2000-10-20
·
Updated
2008-09-10
·
CVE-2000-0685
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic versions 5.1.x
Description
The issue is related to improper access restriction to the PageCompileServlet, allowing remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
Recommendations
For BEA WebLogic versions 5.1.x, restrict access to the PageCompileServlet to prevent unauthorized compilation and execution of Java JHTML code.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic