PT-2005-2720 · Bea · Bea Weblogic Server
Published
2005-05-24
·
Updated
2018-10-30
·
CVE-2005-1748
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and Express versions 7.0 through Service Pack 5
BEA WebLogic Server and Express versions 8.1 through Service Pack 4
Description
The issue concerns the embedded LDAP server, which allows remote anonymous binds. This may enable remote attackers to view user entries or cause a denial of service.
Recommendations
For versions 7.0 through Service Pack 5, consider restricting access to the embedded LDAP server to prevent remote anonymous binds.
For versions 8.1 through Service Pack 4, consider restricting access to the embedded LDAP server to prevent remote anonymous binds.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server