Unrated severityNVD Advisory· Published Dec 1, 2003· Updated Jun 16, 2026
CVE-2003-0623
CVE-2003-0623
Description
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
Affected products
10cpe:2.3:a:bea:tuxedo:6.3:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:bea:tuxedo:6.3:*:*:*:*:*:*:*
- cpe:2.3:a:bea:tuxedo:6.4:*:*:*:*:*:*:*
- cpe:2.3:a:bea:tuxedo:6.5:*:*:*:*:*:*:*
- cpe:2.3:a:bea:tuxedo:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:bea:tuxedo:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:bea:tuxedo:8.1:*:*:*:*:*:*:*
- (no CPE)range: <=8.1
cpe:2.3:a:bea:weblogic_server:4.2:*:enterprise:*:*:*:*:*+ 2 more
- cpe:2.3:a:bea:weblogic_server:4.2:*:enterprise:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:5.0.1:*:enterprise:*:*:*:*:*
- cpe:2.3:a:bea:weblogic_server:5.1:*:enterprise:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jspnvdPatchVendor Advisory
- www.securityfocus.com/bid/8931nvdExploitPatchVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/13561nvd
News mentions
0No linked articles in our index yet.