CVE-2008-0900
Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.
- Affected products
- Bea Weblogic Server
- Bea Weblogic Server
- = 8.1, 9.2, 10.0
- Bea Systems Weblogic Express
- = 9.2, 10.0
- CVSS 2.0
- 6.0 MEDIUM
- EPSS
- 10.0% (95th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-02-22
CVE-2008-0900 at NVD
1 known exploit for CVE-2008-0900
Proof-of-concept code and exploit modules indexed by Sploitus