CVE-2007-2705

medium

Description

Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through SP6, when "deployed in an exploded format," allows remote attackers to list a WebLogic Workshop Directory (wlwdir) parent directory via unspecified vectors.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/34281

http://www.vupen.com/english/advisories/2007/1815

http://www.securitytracker.com/id?1018059

http://osvdb.org/36063

http://dev2dev.bea.com/pub/advisory/239

Details

Source: Mitre, NVD

Published: 2007-05-16

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.004