CVE-2003-0640

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2003
Last modified:
05/09/2008

Description

BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bea:weblogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:*:express:*:*:*:*:*