CVE-2007-2699
Estado: ModificadaAlta (7.1)—
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 29%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://dev2dev.bea.com/pub/advisory/231
- http://osvdb.org/36069
- http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34289
- http://dev2dev.bea.com/pub/advisory/231
- http://osvdb.org/36069
- http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34289
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-2699",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-05-16T01:19:00.000",
"references": [
{
"url": "http://dev2dev.bea.com/pub/advisory/231",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/36069",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25284",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018057",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1815",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34289",
"source": "cve@mitre.org"
},
{
"url": "http://dev2dev.bea.com/pub/advisory/231",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/36069",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/153072/Oracle-Application-Testing-Suite-WebLogic-Server-Administration-Console-War-Deployment.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25284",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018057",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1815",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34289",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative users in the Deployer role to upload arbitrary files."
},
{
"lang": "es",
"value": "La Consola de Administración en BEA WebLogic Express y WebLogic Server 9.0 y 9.1 no hace cumplir correctamente ciertas Políticas de Seguridad del Dominio, lo cual permite a usuarios administradores remotos en el rol de Desplegador (Deployer) enviar ficheros de su elección."
}
],
"lastModified": "2026-06-16T22:40:08.777",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CA97F1A-49F7-4511-8959-D62155491DF5"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EDB38AA-CAC4-4C89-8484-7C2A75F8038F"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCAAE8F1-CB25-4871-BE48-ABF7DFAD8AD6"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17280B97-D499-434E-BD89-FD348E9E2E0C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}