7.5
CVSSv2

CVE-2002-2142

Published: 31/12/2002 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 up to and including 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 6.1

bea weblogic server 7.0

bea weblogic server 7.0.0.1

bea weblogic integration 7.0

bea weblogic server 6.0