BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection.
References
Link Resource
http://dev2dev.bea.com/pub/advisory/141 Patch Vendor Advisory
http://www.osvdb.org/20095 Patch
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-02-01T20:00:00

Updated: 2006-04-04T09:00:00

Reserved: 2006-02-01T00:00:00


Link: CVE-2005-4705

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2005-12-31T05:00:00.000

Modified: 2008-09-05T20:57:35.517


Link: CVE-2005-4705

JSON object: View

cve-icon Redhat Information

No data.