← Vulnerability feed

Vulnerability record · CVE-2000-0681 · published 20 October 2000

CVE-2000-0681: BEA WebLogic proxy plugin buffer overflow via long .JSP URL

Bea · Weblogic Server

The BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated attacker can send such a request and potentially execute arbitrary commands on the server. The flaw is severe because it is network-reachable with no authentication or user interaction required.

10.0 CVSS 2.0 High EPSS 51% · top 1.1%
10.0CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated arbitrary command execution and a high EPSS percentile make this a top-priority flaw despite the lack of KEV listing.

What it is

The BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated attacker can send such a request and potentially execute arbitrary commands on the server. The flaw is severe because it is network-reachable with no authentication or user interaction required.

Impact

Successful exploitation lets a remote attacker execute arbitrary commands with the privileges of the WebLogic proxy plugin process, giving full control over confidentiality, integrity and availability of the affected host.

Attack surface

Reached over the network by sending an HTTP request containing an overly long URL with a .JSP extension to the WebLogic proxy plugin; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware usage is recorded in this data, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor patch referenced in the BEA/SecurityFocus advisories for the WebLogic proxy plugin.
  • If patching is not immediately possible, restrict network access to the proxy plugin to trusted sources and disable it if unused.
  • Enforce URL length limits and reject malformed or oversized .JSP requests at the reverse proxy or WAF.
  • Run the WebLogic proxy plugin with least privilege to limit the impact of command execution.
  • Monitor vendor advisories for updated guidance since the record is old and product version details are absent.

Detection

  • Inspect web and proxy logs for unusually long URLs, especially those ending in .JSP.
  • Alert on proxy plugin process crashes, restarts or abnormal child process creation.
  • Monitor for unexpected command execution or shell activity spawned by the WebLogic proxy plugin process.
  • Correlate repeated oversized .JSP requests from a single source as a possible exploitation attempt.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0681 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3257WebLogic Apache Connector mod_wl stack buffer overflow via HTTP version stringThe Apache Connector (mod_wl) in Oracle WebLogic Server 10.3 and earlier has a stack-based buffer overflow reachable through a long HTTP version stri…EPSS 84%analysed10.0CVE-2007-0417Bea weblogic server vulnerabilityBEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers …EPSS 1.8%10.0CVE-2003-0640Bea weblogic server vulnerabilityBEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and password…EPSS 2.0%10.0CVE-2001-0098BEA WebLogic Server URL buffer overflow allows remote command executionBEA WebLogic Server before 5.1.0 contains a buffer overflow reachable through a long URL beginning with a ".." string. A remote, unauthenticated atta…EPSS 78%analysed10.0CVE-2000-0684Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by di…EPSS 12%10.0CVE-2000-0685Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML …EPSS 12%9.8CVE-2005-1744Bea weblogic server vulnerabilityBEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those user…EPSS 2.1%7.9CVE-2008-0897Bea weblogic server permissions and access controls vulnerabilityUnspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2000-0681), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.