PT-2005-1494 · Bea · Bea Weblogic Server

Publicado

2005-02-15

·

Atualizado

2008-09-05

·

CVE-2005-0432

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 7.0 through 7.0 Service Pack 5 BEA WebLogic Server versions 8.1 through 8.1 Service Pack 3
Description The issue allows remote attackers to guess passwords via brute force attacks because the server generates different login exceptions that suggest why an authentication attempt fails.
Recommendations For BEA WebLogic Server versions 7.0 through 7.0 Service Pack 5, update to a version later than 7.0 Service Pack 5 to resolve the issue. For BEA WebLogic Server versions 8.1 through 8.1 Service Pack 3, update to a version later than 8.1 Service Pack 3 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0432

Produtos afetados

Bea Weblogic Server