BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.
References
Link | Resource |
---|---|
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp | |
http://www.kb.cert.org/vuls/id/999788 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/8320 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/12799 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-03-10T05:00:00
Updated: 2017-07-10T14:57:01
Reserved: 2005-03-10T00:00:00
Link: CVE-2003-1094
JSON object: View
NVD Information
Status : Modified
Published: 2003-12-31T05:00:00.000
Modified: 2017-07-11T01:29:44.180
Link: CVE-2003-1094
JSON object: View
Redhat Information
No data.
CWE