Required CVE Record Information
Description
BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 8320 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: weblogic-gain-privileges(12799) vdb-entryx_transferred
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp x_transferred
- kb.cert.org: VU#999788 third-party-advisoryx_transferred