CVE-2004-1755
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jspPatch
- http://secunia.com/advisories/10725Patch
- http://www.kb.cert.org/vuls/id/858990Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9502Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15826
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jspPatch
- http://secunia.com/advisories/10725Patch
- http://www.kb.cert.org/vuls/id/858990Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9502Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15826
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.