CVE-2000-0685 describes a critical vulnerability in BEA WebLogic Server versions 5.1.x, where the PageCompileServlet fails to restrict access, allowing remote attackers to compile and execute arbitrary Java JHTML code. This flaw carries a CVSS score of 10.0, indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and showing no active community discussion or media coverage, an ExploitDB entry exists (EDB-20125) detailing remote command execution, suggesting exploit code is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.8CPE matchmatch criteria | cpe:2.3:a:bea:weblogic_server:3.1.8:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:a:bea:weblogic_server:4.0.4:*:*:*:*:*:*:* | ||
4.5.1CPE matchmatch criteria | cpe:2.3:a:bea:weblogic_server:4.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.