CVE-2007-2699
BEA WebLogic Express/WebLogic Server 9.0-9.1 - Privilege Escalation
Title source: llmDescription
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by Steven Seeley, sinn3r · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/oats_weblogic_console.rb
References (7)
Scores
EPSS
0.0134
EPSS Percentile
79.7%
Classification
Status
draft
Affected Products (4)
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
Timeline
Published
May 16, 2007
Tracked Since
Feb 18, 2026