Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-0471 | First vendor Publication | 2004-07-07 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown). |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0471 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
6077 | BEA WebLogic Unprivileged Stop/Start BEA WebLogic Express and Server contains a flaw that may allow unprivilege Admin and Operator security roles start and stop server. The issue is due to the start and stop policies for Admin and Operator security roles aren't properly enforced. It is possible that the flaw may allow a local attacker to arbitrarily start and stop the webserver, resulting in a loss of availability. |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:03 |
|
2024-11-28 12:06:06 |
|
2021-05-04 12:02:20 |
|
2021-04-22 01:02:29 |
|
2020-05-23 00:15:48 |
|
2017-07-11 12:01:26 |
|
2016-06-28 15:05:45 |
|
2016-04-26 12:50:11 |
|
2013-05-11 11:41:50 |
|