CVE-2007-2699
high · 7.1The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.
7.1
CVSS
29.3%
EPSS (exploit prob.)
98th
EPSS percentile
2007-05-16
Published
AV:N/AC:H/Au:S/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| bea | weblogic_server | 9.0 |
| bea | weblogic_server | 9.0 |
| bea | weblogic_server | 9.1 |
| bea | weblogic_server | 9.1 |
Check a specific version with /api/v1/cve/match.
References
- http://dev2dev.bea.com/pub/advisory/231
- http://osvdb.org/36069
- http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34289
- http://dev2dev.bea.com/pub/advisory/231
- http://osvdb.org/36069
- http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34289
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2699