CVE Vulnerabilities

CVE-2004-2696

Published: Dec 31, 2004 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an unexpected user identity to be used in an RMI call.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea 6.1 (including) 6.1 (including)
Weblogic_server Bea 6.1-sp1 (including) 6.1-sp1 (including)
Weblogic_server Bea 6.1-sp2 (including) 6.1-sp2 (including)
Weblogic_server Bea 6.1-sp3 (including) 6.1-sp3 (including)
Weblogic_server Bea 6.1-sp4 (including) 6.1-sp4 (including)
Weblogic_server Bea 6.1-sp5 (including) 6.1-sp5 (including)
Weblogic_server Bea 6.1-sp6 (including) 6.1-sp6 (including)
Weblogic_server Bea 7.0 (including) 7.0 (including)
Weblogic_server Bea 7.0-sp1 (including) 7.0-sp1 (including)
Weblogic_server Bea 7.0-sp2 (including) 7.0-sp2 (including)
Weblogic_server Bea 7.0-sp3 (including) 7.0-sp3 (including)
Weblogic_server Bea 7.0-sp4 (including) 7.0-sp4 (including)
Weblogic_server Bea 7.0-sp5 (including) 7.0-sp5 (including)
Weblogic_server Bea 7.0.0.1 (including) 7.0.0.1 (including)
Weblogic_server Bea 7.0.0.1-sp1 (including) 7.0.0.1-sp1 (including)
Weblogic_server Bea 7.0.0.1-sp2 (including) 7.0.0.1-sp2 (including)
Weblogic_server Bea 7.0.0.1-sp3 (including) 7.0.0.1-sp3 (including)
Weblogic_server Bea 7.0.0.1-sp4 (including) 7.0.0.1-sp4 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)
Weblogic_server Bea 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_server Bea 8.1-sp2 (including) 8.1-sp2 (including)

References