CVE-2005-4759
BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently…
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently lose protection of Web Application pages.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/149Patch, Vendor Advisory
- http://secunia.com/advisories/17138Vendor Advisory
- http://www.securityfocus.com/bid/15052
- http://dev2dev.bea.com/pub/advisory/149Patch, Vendor Advisory
- http://secunia.com/advisories/17138Vendor Advisory
- http://www.securityfocus.com/bid/15052
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.