Loading
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.
Cite this page
CVE-2007-2699. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2007-2699
Use Bea vendor hub and Weblogic Server product page to widen CVE-2007-2699 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2008-3257, CVE-2008-0897 and CVE-2008-0901 for nearby disclosures in the same product family.