Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcg8-68f4-v6r7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.

EPSS

Процентиль: 45%
0.00226
Низкий

Связанные уязвимости

nvd
около 20 лет назад

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.

EPSS

Процентиль: 45%
0.00226
Низкий