CVE-2002-2142
Last modified
CVE-2002-2142 is a vulnerability of currently unknown severity. An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bea | Weblogic Integration | 7.0 |
| Bea | Weblogic Server | 6.0 |
| Bea | Weblogic Server | 6.1 |
| Bea | Weblogic Server | 7.0 |
| Bea | Weblogic Server | 7.0.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-2142?
How severe is CVE-2002-2142?
How do I fix CVE-2002-2142?
Are you affected by CVE-2002-2142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
