PT-2005-2720 · Bea · Bea Weblogic Server
CVE-2005-1748
·
Published
2005-05-24
·
Updated
2018-10-30
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and Express versions 7.0 through Service Pack 5
BEA WebLogic Server and Express versions 8.1 through Service Pack 4
Description
The issue concerns the embedded LDAP server, which allows remote anonymous binds. This may enable remote attackers to view user entries or cause a denial of service.
Recommendations
For versions 7.0 through Service Pack 5, consider restricting access to the embedded LDAP server to prevent remote anonymous binds.
For versions 8.1 through Service Pack 4, consider restricting access to the embedded LDAP server to prevent remote anonymous binds.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server