First published: Sat Aug 02 2003(Updated: )
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | ||
Oracle WebLogic Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0640 is considered a critical vulnerability that allows unauthorized privilege escalation.
To fix CVE-2003-0640, ensure that user roles and permissions are correctly configured and apply any relevant security patches provided by the vendor.
CVE-2003-0640 affects BEA WebLogic Server and WebLogic Server Express installations that utilize NodeManager.
Operators with basic user privileges can exploit CVE-2003-0640 to gain administrative privileges.
Exploitation of CVE-2003-0640 can lead to unauthorized access and manipulation of sensitive data within affected WebLogic environments.