Vulnerabilities
Vulnerable Software
Bea:  >> Tuxedo  >> 7.1  Security Vulnerabilities
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
CVSS Score
5.0
EPSS Score
0.068
Published
2003-12-01
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.
CVSS Score
5.0
EPSS Score
0.008
Published
2003-12-01
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
CVSS Score
4.3
EPSS Score
0.005
Published
2003-12-01
The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.
CVSS Score
4.6
EPSS Score
0.001
Published
2001-12-31


Contact Us

Shodan ® - All rights reserved