HomeBeaCVE-2007-2699

CVE-2007-2699

UNKNOWN
7.1CVSS
Published: 2007-05-16
Updated: 2025-04-09
AI Analysis

Description

The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.

CVSS Metrics

Vector
AV:N/AC:H/Au:S/C:C/I:C/A:C
Access Vector
network
Access Cmplx
high
Auth
single
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
BEA
Published
5/16/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

bea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-2699 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com