CVE Vulnerabilities

CVE-2007-0416

Published: Jan 23, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.

Affected Software

NameVendorStart VersionEnd Version
Weblogic_serverBea9.0 (including)9.0 (including)
Weblogic_serverBea9.1 (including)9.1 (including)

References