PT-2005-2720 · Bea · Bea Weblogic Server

Published

2005-05-24

·

Updated

2018-10-30

·

CVE-2005-1748

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and Express versions 7.0 through Service Pack 5 BEA WebLogic Server and Express versions 8.1 through Service Pack 4
Description The issue concerns the embedded LDAP server, which allows remote anonymous binds. This may enable remote attackers to view user entries or cause a denial of service.
Recommendations For versions 7.0 through Service Pack 5, consider restricting access to the embedded LDAP server to prevent remote anonymous binds. For versions 8.1 through Service Pack 4, consider restricting access to the embedded LDAP server to prevent remote anonymous binds.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1748

Affected Products

Bea Weblogic Server