CVE-2000-0682: Medium severity Bea WebLogic Server vulnerability
Published Oct 13, 2000
·Updated
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.
Affected Software
15 affected components
Bea WebLogic Server=5.1-sp11
Bea WebLogic Server=5.1-sp7
Bea WebLogic Server=5.1-sp8
Bea WebLogic Server=5.1-sp2
Bea WebLogic Server=5.1-sp5
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp9
Bea WebLogic Server=5.1-sp3
Bea WebLogic Server=5.1-sp12
Bea WebLogic Server=5.1-sp1
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp6
Bea WebLogic Server=5.1-sp10
Bea WebLogic Server=5.1-sp4
Remediation
Patch Available
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0682?
CVE-2000-0682 is considered to have a medium severity due to the potential exposure of sensitive source code.
2
How do I fix CVE-2000-0682?
To fix CVE-2000-0682, it is recommended to upgrade to a patched version of BEA WebLogic Server beyond 5.1.
3
Who is affected by CVE-2000-0682?
CVE-2000-0682 affects users of BEA WebLogic Server versions 5.1 and its various service packs.
4
What type of vulnerability is CVE-2000-0682?
CVE-2000-0682 is a remote code exposure vulnerability that allows attackers to access source code via manipulated URLs.
5
What are the consequences of CVE-2000-0682?
Exploitation of CVE-2000-0682 could lead to unauthorized access to application source code, potentially revealing sensitive information.