| Vulnerability Name: | CVE-2005-4704 (CCN-22567) | ||||||||
| Assigned: | 2005-10-12 | ||||||||
| Published: | 2005-10-12 | ||||||||
| Updated: | 2008-09-05 | ||||||||
| Summary: | Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-4704 Source: BEA Type: Patch, Vendor Advisory BEA05-85.00 Source: CCN Type: BEA Systems Inc. Web site BEA Product Documentation Source: OSVDB Type: Patch 20094 Source: CCN Type: OSVDB ID: 20094 BEA WebLogic One-way SSL Session Encryption Failure Source: XF Type: UNKNOWN weblogic-ssl-password-information-disclosure(22567) Source: CCN Type: BEA Systems Security Advisory: (BEA05-85.00) Client/server communications that do not specify a user are not protected by the SSL protocol correctly. | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||