PT-2004-1739 · Bea · Weblogic Express+1
Published
2004-07-13
·
Updated
2017-07-11
·
CVE-2004-0652
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 7.0 through 7.0 Service Pack 4
BEA WebLogic Server and WebLogic Express versions 8.1 through 8.1 Service Pack 2
Description
The issue allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
Recommendations
For versions 7.0 through 7.0 Service Pack 4, update to a version later than Service Pack 4 to resolve the issue.
For versions 8.1 through 8.1 Service Pack 2, update to a version later than Service Pack 2 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblogic Express
Oracle Weblogic Server