← All CVEs

CVE-2007-2699

high · 7.1

The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.

7.1
CVSS
29.3%
EPSS (exploit prob.)
98th
EPSS percentile
2007-05-16
Published

AV:N/AC:H/Au:S/C:C/I:C/A:C

Affected products

VendorProductAffected versions
beaweblogic_server9.0
beaweblogic_server9.0
beaweblogic_server9.1
beaweblogic_server9.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2699