CVE-2003-0621 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 8% (pctl 95)
Patch early
A public exploit exists.
Description
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 8.05% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-01 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| bea | tuxedo |
| bea | weblogic server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BEA Tuxedo 6/7/8 and WebLogic Enterprise 4/5 - Input Validation | 2003-10-30 |
References
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp
- http://marc.info/?l=bugtraq&m=106762000607681&w=2
- http://www.securityfocus.com/bid/8931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13559
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp
- http://marc.info/?l=bugtraq&m=106762000607681&w=2
- http://www.securityfocus.com/bid/8931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13559
→ the Explorer · watch your stack · NVD