Description
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13561
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106762000607681&w=2
Patch, Vendor Advisory x_refsource_confirm
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/8931
Scores
EPSS
0.0054
EPSS Percentile
67.8%
Details
Status
published
Products (9)
bea/tuxedo
6.3
bea/tuxedo
6.4
bea/tuxedo
6.5
bea/tuxedo
7.1
bea/tuxedo
8.0
bea/tuxedo
8.1
bea/weblogic_server
4.2
bea/weblogic_server
5.0.1
bea/weblogic_server
5.1
Published
Dec 01, 2003
Tracked Since
Feb 18, 2026