Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 96 bronnen 2 kritiek 28 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2004-2320

MEDIUM · 5.3 CVSS Gepubliceerd: CWE-200

Beschrijving

The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

Vendors

Bea

Affected products

Weblogic Server

References