Vulnerability record · CVE-2000-0681 · published 20 October 2000
CVE-2000-0681: BEA WebLogic proxy plugin buffer overflow via long .JSP URL
Bea · Weblogic Server
The BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated attacker can send such a request and potentially execute arbitrary commands on the server. The flaw is severe because it is network-reachable with no authentication or user interaction required.
Description
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated arbitrary command execution and a high EPSS percentile make this a top-priority flaw despite the lack of KEV listing.
What it is
The BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated attacker can send such a request and potentially execute arbitrary commands on the server. The flaw is severe because it is network-reachable with no authentication or user interaction required.
Impact
Successful exploitation lets a remote attacker execute arbitrary commands with the privileges of the WebLogic proxy plugin process, giving full control over confidentiality, integrity and availability of the affected host.
Attack surface
Reached over the network by sending an HTTP request containing an overly long URL with a .JSP extension to the WebLogic proxy plugin; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is recorded in this data, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor patch referenced in the BEA/SecurityFocus advisories for the WebLogic proxy plugin.
- If patching is not immediately possible, restrict network access to the proxy plugin to trusted sources and disable it if unused.
- Enforce URL length limits and reject malformed or oversized .JSP requests at the reverse proxy or WAF.
- Run the WebLogic proxy plugin with least privilege to limit the impact of command execution.
- Monitor vendor advisories for updated guidance since the record is old and product version details are absent.
Detection
- Inspect web and proxy logs for unusually long URLs, especially those ending in .JSP.
- Alert on proxy plugin process crashes, restarts or abnormal child process creation.
- Monitor for unexpected command execution or shell activity spawned by the WebLogic proxy plugin process.
- Correlate repeated oversized .JSP requests from a single source as a possible exploitation attempt.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/1570 | PatchVendor Advisory |
| http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/1570 | PatchVendor Advisory |
Track CVE-2000-0681 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0681), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.