BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
References
Link | Resource |
---|---|
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_55.00.jsp | |
http://secunia.com/advisories/11359 | |
http://securitytracker.com/id?1009766 | |
http://www.kb.cert.org/vuls/id/352110 | Patch Third Party Advisory US Government Resource |
http://www.osvdb.org/5296 | |
http://www.securityfocus.com/bid/10133 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15865 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2004-07-13T04:00:00
Updated: 2017-07-10T14:57:01
Reserved: 2004-07-09T00:00:00
Link: CVE-2004-0652
JSON object: View
NVD Information
Status : Modified
Published: 2004-08-06T04:00:00.000
Modified: 2017-07-11T01:30:20.840
Link: CVE-2004-0652
JSON object: View
Redhat Information
No data.
CWE