PT-2005-2715 · Bea · Weblogic Express+1

Published

2005-05-24

·

Updated

2018-10-30

·

CVE-2005-1743

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 8.1 through Service Pack 3 BEA WebLogic Server and WebLogic Express versions 7.0 through Service Pack 5
Description The issue arises when a security provider throws an exception, which may cause the server to use an incorrect identity for the thread or fail to audit security exceptions.
Recommendations For versions 8.1 through Service Pack 3, update to a version later than Service Pack 3. For versions 7.0 through Service Pack 5, update to a version later than Service Pack 5. As a temporary workaround, consider restricting access to security-sensitive operations until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1743

Affected Products

Bea Weblogic Server
Weblogic Express