CVE-2005-1744
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-459
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/127Product
- http://secunia.com/advisories/15486Broken Link, Vendor Advisory
- http://securitytracker.com/id?1014049Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/13717Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/0604Broken Link
- http://dev2dev.bea.com/pub/advisory/127Product
- http://secunia.com/advisories/15486Broken Link, Vendor Advisory
- http://securitytracker.com/id?1014049Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/13717Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2005/0604Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.