Lucene search

K
nvd[email protected]NVD:CVE-2008-0900
HistoryFeb 22, 2008 - 9:44 p.m.

CVE-2008-0900

2008-02-2221:44:00
CWE-264
web.nvd.nist.gov
4

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

65.3%

Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.

Affected configurations

Nvd
Node
beaweblogic_serverMatch8.1sp4
OR
beaweblogic_serverMatch8.1sp4express
OR
beaweblogic_serverMatch8.1sp5
OR
beaweblogic_serverMatch8.1sp5express
OR
beaweblogic_serverMatch8.1sp6
OR
beaweblogic_serverMatch8.1sp6express
OR
beaweblogic_serverMatch9.2
OR
beaweblogic_serverMatch9.2mp1
OR
beaweblogic_serverMatch10.0
OR
bea_systemsweblogic_expressMatch9.2mp1
OR
bea_systemsweblogic_expressMatch10.0
VendorProductVersionCPE
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:*
beaweblogic_server8.1cpe:2.3:a:bea:weblogic_server:8.1:sp6:express:*:*:*:*:*
beaweblogic_server9.2cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:*
beaweblogic_server9.2cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:*
beaweblogic_server10.0cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:*
bea_systemsweblogic_express9.2cpe:2.3:a:bea_systems:weblogic_express:9.2:mp1:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

65.3%

Related for NVD:CVE-2008-0900