Vulnerability Name:
CVE-2005-4766 (CCN-22593)
Assigned:
2005-10-11
Published:
2005-10-11
Updated:
2008-09-05
Summary:
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.
CVSS v3 Severity:
5.9 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
5.4 Medium
(CVSS v2 Vector:
AV:N/AC:H/Au:N/C:C/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
None
Availibility (A):
None
5.4 Medium
(CCN CVSS v2 Vector:
AV:N/AC:H/Au:N/C:C/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2005-4766
Source: BEA
Type: Patch, Vendor Advisory
BEA05-103.00
Source: CCN
Type: BEA Systems Inc. Web site
BEA Product Documentation
Source: CCN
Type: SA17138
BEA WebLogic 24 Vulnerabilities and Security Issues
Source: SECUNIA
Type: Patch, Vendor Advisory
17138
Source: CCN
Type: OSVDB ID: 20110
BEA WebLogic Multicast Message Cleartext Information Disclosure
Source: BID
Type: Patch
15052
Source: CCN
Type: BID-15052
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
Source: XF
Type: UNKNOWN
weblogic-multicast-message-disclosure(22593)
Source: CCN
Type: BEA Systems Security Advisory: (BEA05-103.00)
Multicast data is not encrypted.
Vulnerable Configuration:
Configuration 1
:
cpe:/a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:*:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp1:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp2:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp4:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:7.0:sp5:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:*:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:*:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp1:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp2:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp3:win32:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*
OR
cpe:/a:bea:weblogic_server:8.1:sp4:win32:*:*:*:*:*
Denotes that component is vulnerable
BACK
bea
weblogic server 7.0
bea
weblogic server 7.0
bea
weblogic server 7.0
bea
weblogic server 7.0 sp1
bea
weblogic server 7.0 sp1
bea
weblogic server 7.0 sp1
bea
weblogic server 7.0 sp2
bea
weblogic server 7.0 sp2
bea
weblogic server 7.0 sp2
bea
weblogic server 7.0 sp3
bea
weblogic server 7.0 sp3
bea
weblogic server 7.0 sp3
bea
weblogic server 7.0 sp4
bea
weblogic server 7.0 sp4
bea
weblogic server 7.0 sp4
bea
weblogic server 7.0 sp5
bea
weblogic server 7.0 sp5
bea
weblogic server 7.0 sp5
bea
weblogic server 8.1
bea
weblogic server 8.1
bea
weblogic server 8.1
bea
weblogic server 8.1 sp1
bea
weblogic server 8.1 sp1
bea
weblogic server 8.1 sp1
bea
weblogic server 8.1 sp2
bea
weblogic server 8.1 sp2
bea
weblogic server 8.1 sp2
bea
weblogic server 8.1 sp3
bea
weblogic server 8.1 sp3
bea
weblogic server 8.1 sp3
bea
weblogic server 8.1 sp4
bea
weblogic server 8.1 sp4
bea
weblogic server 8.1 sp4