VulnerabilityModified
CVE-2005-1742
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."
MEDIUM 5.0EPSS 3.03%
Does this matter?
Lower severity and a low EPSS score (3.03%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.03% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server · oracle/weblogic portal
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/125Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0602
- http://dev2dev.bea.com/pub/advisory/125Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0602
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.