CVE-2000-1238: High severity Bea WebLogic Server vulnerability
Published Dec 31, 2000
·Updated
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
Affected Software
14 affected components
Bea WebLogic Server=5.1-sp2
Bea WebLogic Server=5.1-sp5
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp1
Bea WebLogic Server=5.1-sp6
Bea WebLogic Server=5.1-sp4
Bea WebLogic Server=5.1-sp3
Bea WebLogic Server=5.1-sp3
Bea WebLogic Server=5.1-sp5
Bea WebLogic Server=5.1-sp1
Bea WebLogic Server=5.1
Bea WebLogic Server=5.1-sp6
Bea WebLogic Server=5.1-sp4
Bea WebLogic Server=5.1-sp2
Remediation
Patch Available
Event History
Dec 31, 2000
CVE Published
05:00 AM
Nov 16, 2005
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1238?
CVE-2000-1238 has a moderate severity level as it allows attackers to bypass access controls.
2
How do I fix CVE-2000-1238?
To fix CVE-2000-1238, ensure that you upgrade to a patched version of WebLogic Server beyond 5.1 SP6.
3
What versions of WebLogic Server are affected by CVE-2000-1238?
CVE-2000-1238 affects WebLogic Server versions 5.1 SP1 through SP6.
4
What are the potential impacts of CVE-2000-1238?
CVE-2000-1238 could lead to unauthorized access to restricted JSP or servlet pages.
5
Can CVE-2000-1238 be exploited remotely?
Yes, CVE-2000-1238 can be exploited remotely by attackers leveraging specific URL patterns.