PT-2005-5427 · Bea · Bea Weblogic Server+1
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-4764
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 7.0, 8.1, 9.0
Description
The issue allows remote attackers who know or guess the admin account name to cause a denial of service by blocking admin logins, as the server locks out the admin user account after multiple incorrect password guesses.
Recommendations
For versions 7.0, 8.1, 9.0, consider implementing a workaround to limit the number of incorrect login attempts or temporarily restrict access to the admin login functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server
Weblogic Express