CVE-2003-0621: Medium severity Bea Tuxedo vulnerability
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0621?
CVE-2003-0621 is considered a medium-severity vulnerability due to the potential information disclosure it allows.
How do I fix CVE-2003-0621?
To fix CVE-2003-0621, update BEA Tuxedo to a version later than 8.1 or apply patches provided by the vendor.
What software versions are affected by CVE-2003-0621?
CVE-2003-0621 affects BEA Tuxedo versions 6.3, 6.4, 6.5, 7.1, 8.0, and 8.1, along with Oracle WebLogic Server versions 4.2, 5.0.1, and 5.1.
What kind of attacks can be launched due to CVE-2003-0621?
Due to CVE-2003-0621, attackers can determine the existence of files outside of the web root, potentially leading to further information disclosure.
Is CVE-2003-0621 exploitable remotely?
Yes, CVE-2003-0621 can be exploited remotely as it involves the Administration Console of BEA Tuxedo allowing external access.