PT-2005-2715 · Bea · Weblogic Express+1
Published
2005-05-24
·
Updated
2018-10-30
·
CVE-2005-1743
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 through Service Pack 3
BEA WebLogic Server and WebLogic Express versions 7.0 through Service Pack 5
Description
The issue arises when a security provider throws an exception, which may cause the server to use an incorrect identity for the thread or fail to audit security exceptions.
Recommendations
For versions 8.1 through Service Pack 3, update to a version later than Service Pack 3.
For versions 7.0 through Service Pack 5, update to a version later than Service Pack 5.
As a temporary workaround, consider restricting access to security-sensitive operations until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server
Weblogic Express