← Vulnerability feed

Vulnerability record · CVE-2001-0098 · published 12 February 2001

CVE-2001-0098: BEA WebLogic Server URL buffer overflow allows remote command execution

Bea · Weblogic Server

BEA WebLogic Server before 5.1.0 contains a buffer overflow reachable through a long URL beginning with a ".." string. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary commands on the server. The flaw is severe because it requires no credentials and yields full control of the affected host.

10.0 CVSS 2.0 High EPSS 78% · top 0.4%
10.0CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and very high EPSS, though the product is legacy and likely rare in current environments.

What it is

BEA WebLogic Server before 5.1.0 contains a buffer overflow reachable through a long URL beginning with a ".." string. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary commands on the server. The flaw is severe because it requires no credentials and yields full control of the affected host.

Impact

An attacker gains arbitrary command execution with the privileges of the WebLogic service, which typically means full compromise of the server and any data or credentials it holds.

Attack surface

Reachable over the network via HTTP by sending a crafted long URL starting with ".."; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.784, 99.6th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade BEA WebLogic Server to version 5.1.0 or later, which resolves the overflow.
  • If upgrade is not immediately possible, restrict network access to the WebLogic HTTP listener to trusted hosts only.
  • Run the WebLogic service under a low-privilege account to limit the impact of command execution.
  • Monitor vendor advisories and apply any backported fixes for the affected branch.

Detection

  • Inspect web server and WebLogic access logs for unusually long request URLs, especially those beginning with "..".
  • Alert on URL lengths exceeding normal application baselines or containing repeated dot sequences.
  • Monitor for unexpected child processes spawned by the WebLogic service account.
  • Watch for outbound connections from the WebLogic host that do not match normal application traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0098 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3257WebLogic Apache Connector mod_wl stack buffer overflow via HTTP version stringThe Apache Connector (mod_wl) in Oracle WebLogic Server 10.3 and earlier has a stack-based buffer overflow reachable through a long HTTP version stri…EPSS 84%analysed10.0CVE-2007-0417Bea weblogic server vulnerabilityBEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers …EPSS 1.8%10.0CVE-2003-0640Bea weblogic server vulnerabilityBEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and password…EPSS 2.0%10.0CVE-2000-0681BEA WebLogic proxy plugin buffer overflow via long .JSP URLThe BEA WebLogic server proxy plugin contains a buffer overflow that is triggered by a long URL ending in a .JSP extension. A remote, unauthenticated…EPSS 51%analysed10.0CVE-2000-0684Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by di…EPSS 12%10.0CVE-2000-0685Bea weblogic server vulnerabilityBEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML …EPSS 12%9.8CVE-2005-1744Bea weblogic server vulnerabilityBEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those user…EPSS 2.1%7.9CVE-2008-0897Bea weblogic server permissions and access controls vulnerabilityUnspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2001-0098), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.