CVE Vulnerabilities

CVE-2005-4756

Published: Dec 31, 2005 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple PrincipalValidators, which might allow attackers to gain privileges.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea 7.0 (including) 7.0 (including)
Weblogic_server Bea 7.0-sp1 (including) 7.0-sp1 (including)
Weblogic_server Bea 7.0-sp2 (including) 7.0-sp2 (including)
Weblogic_server Bea 7.0-sp3 (including) 7.0-sp3 (including)
Weblogic_server Bea 7.0-sp4 (including) 7.0-sp4 (including)
Weblogic_server Bea 7.0-sp5 (including) 7.0-sp5 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)
Weblogic_server Bea 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_server Bea 8.1-sp2 (including) 8.1-sp2 (including)
Weblogic_server Bea 8.1-sp3 (including) 8.1-sp3 (including)
Weblogic_server Bea 8.1-sp4 (including) 8.1-sp4 (including)

References