CVE-2000-0684: Critical severity Bea WebLogic Server vulnerability
Published Oct 13, 2000
·Updated
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
Affected Software
3 affected components
Bea WebLogic Server=4.5.1
Bea WebLogic Server=3.1.8
Bea WebLogic Server=4.0.4
Remediation
Patch Available
Event History
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0684?
CVE-2000-0684 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2000-0684?
To fix CVE-2000-0684, you should update your BEA WebLogic Server to a version that addresses this vulnerability.
3
What are the potential impacts of CVE-2000-0684?
The potential impacts of CVE-2000-0684 include unauthorized access to sensitive information and the execution of arbitrary Java code.
4
Which versions of WebLogic Server are affected by CVE-2000-0684?
CVE-2000-0684 affects BEA WebLogic Server versions 3.1.8, 4.0.4, and 4.5.1.
5
Can CVE-2000-0684 be exploited remotely?
Yes, CVE-2000-0684 can be exploited remotely, allowing attackers to invoke the JSPServlet and execute malicious code.