CVE-2004-0713
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2004
Last modified:
03/04/2025
Description
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:*:express:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:*:win32:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp1:win32:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp2:win32:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp3:win32:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:* | ||
| cpe:2.3:a:bea:weblogic_server:6.1:sp4:win32:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp
- http://www.kb.cert.org/vuls/id/658878
- http://www.securityfocus.com/bid/10185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15928
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp
- http://www.kb.cert.org/vuls/id/658878
- http://www.securityfocus.com/bid/10185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15928



