VULNERABILITY INTELLIGENCE
CVE-2004-0652
CVSS score7.2 HIGH
EPSS probability0.39%
CISA KEVNot currently listed
Published2004-08-06
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Description
BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
Primary references
- cve@mitre.org
- cve@mitre.org
- cve@mitre.org
- cve@mitre.org — Patch, Third Party Advisory, US Government Resource
- cve@mitre.org
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Third Party Advisory, US Government Resource
- af854a3a-2127-422b-91ae-364da2661108