CVE-2002-2142: High severity Bea WebLogic Server vulnerability
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify servlet mapping URL patterns used by the undocumented Servlet 2.3 extension so each pattern begins with a '/' character to ensure proper enforcement of role mappings and policies.
Servlet mappings (Servlet 2.3 undocumented extension) URL pattern leading slash = prepend '/' to URL patterns - Operational
After upgrading to WebLogic Server and Express 7.0 Service Pack 1, review and validate role mappings and security policies for applications that use the undocumented Servlet mapping extension to ensure access controls are correctly enforced.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2142?
CVE-2002-2142 is classified as a high severity vulnerability due to the potential for bypassing security restrictions.
How do I fix CVE-2002-2142?
To fix CVE-2002-2142, upgrade to a secure version of Oracle WebLogic Server or apply available patches provided by the vendor.
Which versions of WebLogic Server are affected by CVE-2002-2142?
CVE-2002-2142 affects BEA WebLogic Server versions 6.0, 6.1, and 7.0 up to 7.0.0.1.
What kind of impact can CVE-2002-2142 have on my application?
CVE-2002-2142 can allow unauthorized users to access restricted resources, potentially compromising sensitive data.
Is CVE-2002-2142 still relevant today?
Although CVE-2002-2142 was reported a while ago, it remains relevant for organizations still using the affected versions of WebLogic Server.