CVE-2000-0683: Medium severity Bea WebLogic Server vulnerability
Published Oct 13, 2000
·Updated
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /.shtml/ into the URL, which invokes the SSIServlet.
Affected Software
15 affected components
Bea WebLogic Server=5.1-sp11
Bea WebLogic Server=5.1-sp7
Bea WebLogic Server=5.1-sp8
Bea WebLogic Server=5.1-sp2
Bea WebLogic Server=5.1-sp5
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp9
Bea WebLogic Server=5.1-sp3
Bea WebLogic Server=5.1-sp12
Bea WebLogic Server=5.1-sp1
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp6
Bea WebLogic Server=5.1-sp10
Bea WebLogic Server=5.1-sp4
Remediation
Patch Available
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0683?
CVE-2000-0683 is considered to be of medium severity due to its ability to expose sensitive source code.
2
How do I fix CVE-2000-0683?
To fix CVE-2000-0683, upgrade to a patched version of BEA WebLogic Server beyond 5.1.x version.
3
What systems are affected by CVE-2000-0683?
CVE-2000-0683 affects multiple versions of BEA WebLogic Server 5.1 including all service packs.
4
Can CVE-2000-0683 lead to data leakage?
Yes, CVE-2000-0683 can lead to data leakage by allowing unauthorized users to read the source code of parsed pages.
5
Is CVE-2000-0683 specific to a particular application?
CVE-2000-0683 is specific to BEA WebLogic Server, a platform for building and managing web applications.