CVE-2003-1438
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that…
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-26.01.jspPatch
- http://www.securityfocus.com/bid/6717
- http://www.securitytracker.com/id?1006018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11221
- http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-26.01.jspPatch
- http://www.securityfocus.com/bid/6717
- http://www.securitytracker.com/id?1006018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11221
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.