← All CVEs

CVE-2000-0685

high · 10

BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.

10
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2000-10-20
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
beaweblogic_server3.1.8
beaweblogic_server4.0.4
beaweblogic_server4.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2000-0685