CVE-2002-2141: High severity Bea WebLogic Server vulnerability
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2141?
CVE-2002-2141 is considered a medium severity vulnerability due to its potential to expose unauthorized access.
How do I fix CVE-2002-2141?
To resolve CVE-2002-2141, ensure to properly manage and re-establish security constraints and roles after undeploying applications.
What are the affected versions in CVE-2002-2141?
CVE-2002-2141 affects BEA WebLogic Server versions 7.0 and 7.0.0.1.
What systems are impacted by CVE-2002-2141?
CVE-2002-2141 impacts systems running BEA WebLogic Server and Express configured for Servlets and EJBs.
What could happen if CVE-2002-2141 is exploited?
Exploitation of CVE-2002-2141 could allow attackers to gain unauthorized access to servlets or EJBs that lack proper security constraints.