The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://dev2dev.bea.com/pub/advisory/131 - Vendor Advisory | |
References | () http://secunia.com/advisories/15486 - Vendor Advisory | |
References | () http://securitytracker.com/id?1014049 - | |
References | () http://www.securityfocus.com/bid/13717 - | |
References | () http://www.vupen.com/english/advisories/2005/0608 - |
Information
Published : 2005-05-24 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-1748
Mitre link : CVE-2005-1748
CVE.ORG link : CVE-2005-1748
JSON object : View
Products Affected
oracle
- weblogic_portal
bea
- weblogic_server
CWE