CVE-2002-2177: Low severity Bea WebLogic Server vulnerability
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2177?
CVE-2002-2177 has a medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2002-2177?
To fix CVE-2002-2177, upgrade to a patched version of BEA WebLogic Server or apply any recommended security updates.
What impact does CVE-2002-2177 have on affected systems?
CVE-2002-2177 can allow remote attackers to receive information intended for other users, posing significant privacy risks.
Which versions are affected by CVE-2002-2177?
CVE-2002-2177 affects BEA WebLogic Server and Express versions 6.1, 6.1-sp1, and 7.0 up to 7.0.0.1.
Who is targeted by the CVE-2002-2177 vulnerability?
CVE-2002-2177 primarily targets users of BEA WebLogic Server who may inadvertently expose sensitive data to unauthorized parties.