Total vulnerabilities in the database
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "" as wildcards as if they were the legal "/" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.
Software | From | Fixed in |
---|---|---|
bea / weblogic_server | 8.1 | 8.1.x |
bea / weblogic_server | 7.0-sp2 | 7.0-sp2.x |
bea / weblogic_server | 7.0-sp4 | 7.0-sp4.x |
bea / weblogic_server | 7.0 | 7.0.x |
bea / weblogic_server | 7.0-sp3 | 7.0-sp3.x |
bea / weblogic_server | 8.1-sp1 | 8.1-sp1.x |
bea / weblogic_server | 7.0-sp1 | 7.0-sp1.x |