CVE-2003-1221

BEA WebLogic Express & Server <8.1 SP 1 - Info Disclosure

Title source: llm
STIX 2.1

Description

BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.

References (2)

Core 2
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9034
Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/32

Scores

EPSS 0.0038
EPSS Percentile 59.8%

Details

Status published
Products (3)
bea/weblogic_server 7.0 (13 CPE variants)
bea/weblogic_server 7.0.0.1 (9 CPE variants)
bea/weblogic_server 8.1 (4 CPE variants)
Published Dec 31, 2003
Tracked Since Feb 18, 2026