BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
References
Link | Resource |
---|---|
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp | |
http://www.secunia.com/advisories/9232/ | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2003-08-02T04:00:00
Updated: 2005-01-20T10:00:00
Reserved: 2003-08-01T00:00:00
Link: CVE-2003-0640
JSON object: View
NVD Information
Status : Analyzed
Published: 2003-08-27T04:00:00.000
Modified: 2008-09-05T20:34:51.407
Link: CVE-2003-0640
JSON object: View
Redhat Information
No data.
CWE