PT-2005-5369 · Bea · Oracle Weblogic Server+1
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-4704
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 6.1 through SP7
BEA WebLogic Server and WebLogic Express versions 7.0 through SP6
BEA WebLogic Server and WebLogic Express versions 8.1 through SP3
Description
The issue causes an unencrypted protocol to be used in certain circumstances when SSL is intended, resulting in user credentials being sent across the network in cleartext. This allows remote attackers to gain privileges.
Recommendations
For versions 6.1 through SP7, consider disabling SSL until a patch is available to prevent the use of unencrypted protocols.
For versions 7.0 through SP6, restrict access to sensitive operations to minimize the risk of exploitation.
For versions 8.1 through SP3, avoid using the affected protocol until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblogic Express
Oracle Weblogic Server