VulnerabilityModified
CVE-2003-0621
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
MEDIUM 5.0EPSS 6.93%
Does this matter?
Lower severity and a low EPSS score (6.93%). Track it; it rarely justifies an emergency change on its own.
Description
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.93% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- bea/tuxedo · bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jspPatch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=106762000607681&w=2
- http://www.securityfocus.com/bid/8931Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13559
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jspPatch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=106762000607681&w=2
- http://www.securityfocus.com/bid/8931Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13559
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.