CVE-2003-0623: XSS
Published Nov 5, 2003
·Updated
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
Affected Software
9 affected components
Bea Tuxedo=8.0
Bea Tuxedo=7.1
Bea WebLogic Server=4.2
Bea Tuxedo=6.5
Bea WebLogic Server=5.1
Bea Tuxedo=6.3
Bea Tuxedo=6.4
Bea Tuxedo=8.1
Bea WebLogic Server=5.0.1
Remediation
Patch Available
Event History
Nov 5, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 1, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0623?
CVE-2003-0623 has a moderate severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2003-0623?
To fix CVE-2003-0623, update BEA Tuxedo or WebLogic Server to a version that is not vulnerable.
3
What systems are affected by CVE-2003-0623?
CVE-2003-0623 affects BEA Tuxedo versions 6.3 to 8.1 and Oracle WebLogic Server versions 4.2 to 5.1.
4
What type of vulnerability is CVE-2003-0623?
CVE-2003-0623 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2003-0623 be exploited remotely?
Yes, CVE-2003-0623 can be exploited by remote attackers to inject arbitrary web scripts.