Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4799-f54j-42m9

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "" as wildcards as if they were the legal "/" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.

The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "" as wildcards as if they were the legal "/" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.

EPSS

Процентиль: 75%
0.00905
Низкий

Связанные уязвимости

nvd
больше 21 года назад

The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.

EPSS

Процентиль: 75%
0.00905
Низкий