CVE-2000-0812

Sun Java System Web Server - Remote Code Execution via JSP Servlet Upload

Title source: llm
STIX 2.1

Description

The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5135
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1600
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.securityfocus.com/templates/advisory.html?id=2542

Scores

EPSS 0.0255
EPSS Percentile 85.7%

Details

Status published
Products (4)
sun/java_system_web_server 1.1.2
sun/java_system_web_server 1.1.3
sun/java_system_web_server 1.1_beta
sun/java_system_web_server 2.0
Published Nov 14, 2000
Tracked Since Feb 18, 2026