CVE-2005-1743
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server · oracle/weblogic portal
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/126Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0603
- http://dev2dev.bea.com/pub/advisory/126Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0603
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.