Vulnerability Name: | CCN-11219 | ||||||
Published: | 2001-11-09 | ||||||
Updated: | 2001-11-09 | ||||||
Summary: | The Certificate Signature Request (CSR) Generator servlet in BEA WebLogic Server and Express generates insecure private keys when a user does not choose to use a random string. This would result in the generation of private keys that would be easier to guess. If an attacker could guess a user's private key, the attacker could use the key to obtain sensitive information or possibly gain unauthorized access or elevated privileges on the server. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: XF Type: UNKNOWN weblogic-csr-insecure-key(11219) Source: CCN Type: BEA Systems, Inc. Security Advisory (BEA01-12.01) Clarification in documentation for the CSR Generator Servlet for BEA WebLogic Server and BEA WebLogic Server Express | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |