First published: Fri Oct 13 2000(Updated: )
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =4.5.1 | |
Oracle WebLogic Server | =3.1.8 | |
Oracle WebLogic Server | =4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0685 is considered a high severity vulnerability because it allows remote attackers to execute arbitrary Java code.
To fix CVE-2000-0685, you should upgrade your BEA WebLogic Server to a version that mitigates this vulnerability.
CVE-2000-0685 affects BEA WebLogic Server versions 4.5.1, 4.0.4, and 3.1.8.
CVE-2000-0685 allows attackers to compile and execute Java JHTML code by accessing the improperly secured PageCompileServlet.
CVE-2000-0685 presents a significant risk for legacy applications still using affected versions of BEA WebLogic Server.