CVE Vulnerabilities

CVE-2006-2471

Published: May 19, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to T3 clients, (2) internal sensitive information using GetIORServlet, (3) certain server details in exceptions when invalid XML is provided, and (4) a stack trace in a SOAP fault.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea 6.1 (including) 6.1 (including)
Weblogic_server Bea 6.1-sp1 (including) 6.1-sp1 (including)
Weblogic_server Bea 6.1-sp2 (including) 6.1-sp2 (including)
Weblogic_server Bea 6.1-sp3 (including) 6.1-sp3 (including)
Weblogic_server Bea 6.1-sp4 (including) 6.1-sp4 (including)
Weblogic_server Bea 6.1-sp5 (including) 6.1-sp5 (including)
Weblogic_server Bea 6.1-sp6 (including) 6.1-sp6 (including)
Weblogic_server Bea 6.1-sp7 (including) 6.1-sp7 (including)
Weblogic_server Bea 7.0 (including) 7.0 (including)
Weblogic_server Bea 7.0-sp1 (including) 7.0-sp1 (including)
Weblogic_server Bea 7.0-sp2 (including) 7.0-sp2 (including)
Weblogic_server Bea 7.0-sp3 (including) 7.0-sp3 (including)
Weblogic_server Bea 7.0-sp4 (including) 7.0-sp4 (including)
Weblogic_server Bea 7.0-sp5 (including) 7.0-sp5 (including)
Weblogic_server Bea 7.0-sp6 (including) 7.0-sp6 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)
Weblogic_server Bea 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_server Bea 8.1-sp2 (including) 8.1-sp2 (including)
Weblogic_server Bea 8.1-sp3 (including) 8.1-sp3 (including)
Weblogic_server Bea 8.1-sp4 (including) 8.1-sp4 (including)

References