BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2000-10-13T04:00:00

Updated: 2005-11-02T10:00:00

Reserved: 2000-09-19T00:00:00


Link: CVE-2000-0684

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2000-10-20T04:00:00.000

Modified: 2008-09-10T19:05:37.103


Link: CVE-2000-0684

JSON object: View

cve-icon Redhat Information

No data.