CVE Vulnerabilities

CVE-2007-2695

Published: May 16, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process external requests on behalf of a system identity, which allows remote attackers to access administrative data or functionality.

Affected Software

NameVendorStart VersionEnd Version
Weblogic_serverBea6.1 (including)6.1 (including)
Weblogic_serverBea6.1-sp1 (including)6.1-sp1 (including)
Weblogic_serverBea6.1-sp2 (including)6.1-sp2 (including)
Weblogic_serverBea6.1-sp3 (including)6.1-sp3 (including)
Weblogic_serverBea6.1-sp4 (including)6.1-sp4 (including)
Weblogic_serverBea6.1-sp5 (including)6.1-sp5 (including)
Weblogic_serverBea6.1-sp6 (including)6.1-sp6 (including)
Weblogic_serverBea6.1-sp7 (including)6.1-sp7 (including)
Weblogic_serverBea7.0 (including)7.0 (including)
Weblogic_serverBea7.0-sp1 (including)7.0-sp1 (including)
Weblogic_serverBea7.0-sp2 (including)7.0-sp2 (including)
Weblogic_serverBea7.0-sp3 (including)7.0-sp3 (including)
Weblogic_serverBea7.0-sp4 (including)7.0-sp4 (including)
Weblogic_serverBea7.0-sp5 (including)7.0-sp5 (including)
Weblogic_serverBea7.0-sp6 (including)7.0-sp6 (including)
Weblogic_serverBea7.0-sp7 (including)7.0-sp7 (including)
Weblogic_serverBea8.1 (including)8.1 (including)
Weblogic_serverBea8.1-sp1 (including)8.1-sp1 (including)
Weblogic_serverBea8.1-sp2 (including)8.1-sp2 (including)
Weblogic_serverBea8.1-sp3 (including)8.1-sp3 (including)
Weblogic_serverBea8.1-sp4 (including)8.1-sp4 (including)
Weblogic_serverBea8.1-sp5 (including)8.1-sp5 (including)
Weblogic_serverBea9.0 (including)9.0 (including)
Weblogic_serverBea9.1 (including)9.1 (including)
Weblogic_serverBea9.1-ga (including)9.1-ga (including)

References