CVE-2006-0432
Published Jan 25, 2006
Last updated 7 years ago
Overview
- Description
- Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CA97F1A-49F7-4511-8959-D62155491DF5" }, { "criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EDB38AA-CAC4-4C89-8484-7C2A75F8038F" } ], "operator": "OR" } ] } ]