PT-2005-5420 · Bea · Bea Weblogic Server+1

Published

2005-12-31

·

Updated

2018-09-27

·

CVE-2005-4757

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 8.1 SP3 and earlier BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier
Description The issue is related to the improper handling of a "/" (slash) servlet root URL pattern, which could allow remote attackers to bypass intended servlet protections.
Recommendations For versions 8.1 SP3 and earlier, update to a version later than 8.1 SP3 to resolve the issue. For versions 7.0 SP5 and earlier, update to a version later than 7.0 SP5 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4757

Affected Products

Bea Weblogic Server
Weblogic Express