PT-2005-2715 · Bea · Weblogic Express+1
Publicado
2005-05-24
·
Atualizado
2018-10-30
·
CVE-2005-1743
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 through Service Pack 3
BEA WebLogic Server and WebLogic Express versions 7.0 through Service Pack 5
Description
The issue arises when a security provider throws an exception, which may cause the server to use an incorrect identity for the thread or fail to audit security exceptions.
Recommendations
For versions 8.1 through Service Pack 3, update to a version later than Service Pack 3.
For versions 7.0 through Service Pack 5, update to a version later than Service Pack 5.
As a temporary workaround, consider restricting access to security-sensitive operations until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bea Weblogic Server
Weblogic Express