VulnerabilityModified
CVE-2005-1748
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.
MEDIUM 5.0EPSS 2.63%
Does this matter?
Lower severity and a low EPSS score (2.63%). Track it; it rarely justifies an emergency change on its own.
Description
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server · oracle/weblogic portal
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/131Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0608
- http://dev2dev.bea.com/pub/advisory/131Vendor Advisory
- http://secunia.com/advisories/15486Vendor Advisory
- http://securitytracker.com/id?1014049
- http://www.securityfocus.com/bid/13717
- http://www.vupen.com/english/advisories/2005/0608
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.