CVE-2007-2694: XSS
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0 GA, and 9.1 GA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2694?
CVE-2007-2694 is considered a medium severity vulnerability due to the potential for remote attacks using cross-site scripting.
How do I fix CVE-2007-2694?
To fix CVE-2007-2694, upgrade to a patched version of BEA WebLogic Server that addresses the XSS vulnerabilities.
Which versions of BEA WebLogic Server are affected by CVE-2007-2694?
CVE-2007-2694 affects BEA WebLogic Server versions 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, and 9.0 GA.
What type of vulnerability is CVE-2007-2694?
CVE-2007-2694 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2007-2694 be exploited without user interaction?
Yes, CVE-2007-2694 can potentially be exploited without user interaction, allowing attackers to inject malicious scripts.