PT-2006-1487 · Bea · Bea Weblogic Server+1

Published

2006-01-25

·

Updated

2008-09-05

·

CVE-2006-0420

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 7.0 through SP6 BEA WebLogic Server and WebLogic Express versions 8.1 through SP4
Description The issue is related to how the software handles relative forwarding when used by servlets. This can be exploited by remote attackers to cause a denial of service, specifically a slowdown, by triggering "looping stack overflow errors" through unknown attack vectors.
Recommendations For versions 7.0 through SP6, update to a version that properly handles relative forwarding to prevent denial of service attacks. For versions 8.1 through SP4, update to a version that properly handles relative forwarding to prevent denial of service attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0420

Affected Products

Bea Weblogic Server
Weblogic Express