CVE-2000-0681Improper Restriction of Operations within the Bounds of a Memory Buffer in Weblogic Server

4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
15.1%
top 5.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 20
Latest updateApr 30

Description

Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cghg-rv7h-488q: Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a2022-04-30
CVEList
CVE-2000-0681: Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a2000-10-13

📄Research Papers

1
arXiv
Encoding a Taxonomy of Web Attacks with Different-Length Vectors2002-10-29
CVE-2000-0681 — BEA Weblogic Server vulnerability | cvebase