VulnerabilityModified
CVE-2003-1290
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).
MEDIUM 5.0EPSS 2.37%
Does this matter?
Lower severity and a low EPSS score (2.37%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.37% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/162Vendor Advisory
- http://secunia.com/advisories/10218Patch, Vendor Advisory
- http://secunia.com/advisories/18396Vendor Advisory
- http://www.osvdb.org/3064
- http://www.securityfocus.com/bid/16215
- http://www.securityfocus.com/bid/9034Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13752
- http://dev2dev.bea.com/pub/advisory/162Vendor Advisory
- http://secunia.com/advisories/10218Patch, Vendor Advisory
- http://secunia.com/advisories/18396Vendor Advisory
- http://www.osvdb.org/3064
- http://www.securityfocus.com/bid/16215
- http://www.securityfocus.com/bid/9034Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13752
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.