CVE-2003-1094

BEA WebLogic Server & Express <7.0 SP3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/12799
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8320
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/999788

Scores

EPSS 0.0213
EPSS Percentile 84.4%

Details

Status published
Products (1)
bea/weblogic_server 7.0 sp3 (3 CPE variants)
Published Dec 31, 2003
Tracked Since Feb 18, 2026