Required CVE Record Information
Description
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.
References 3 Total
- dev2dev.bea.com: BEA05-93.00 vendor-advisory
- securityfocus.com: 15052 vdb-entry
- secunia.com: 17138 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- dev2dev.bea.com: BEA05-93.00 vendor-advisoryx_transferred
- securityfocus.com: 15052 vdb-entryx_transferred
- secunia.com: 17138 third-party-advisoryx_transferred