CVE-2003-1095
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-27.jsp
- http://www.kb.cert.org/vuls/id/691153Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7130Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11555
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-27.jsp
- http://www.kb.cert.org/vuls/id/691153Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7130Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11555
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.