BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.

Subscriptions

Vendors Products
Weblogic Server Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2003-1084 BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T02:12:36.092Z

Reserved: 2005-03-10T00:00:00.000Z

Link: CVE-2003-1094

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2003-12-31T05:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2003-1094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses