| Vulnerability Name: | CVE-2006-0429 (CCN-24298) | ||||||||
| Assigned: | 2006-01-23 | ||||||||
| Published: | 2006-01-23 | ||||||||
| Updated: | 2017-07-20 | ||||||||
| Summary: | BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Other | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-0429 Source: BEA Type: Patch, Vendor Advisory BEA06-116.00 Source: CCN Type: BEA Systems Inc. Web site BEA Product Documentation Source: CCN Type: SA18592 BEA WebLogic Server/Express Vulnerabilities and Security Issues Source: SECUNIA Type: Patch, Vendor Advisory 18592 Source: CCN Type: SECTRACK ID: 1015528 BEA WebLogic Multiple Bugs Let Remote Users Deny Service, Obtain Information, and Access Restricted Resources Source: SECTRACK Type: Patch 1015528 Source: OSVDB Type: UNKNOWN 22773 Source: CCN Type: OSVDB ID: 22773 BEA WebLogic Security Provider Activiation Weakness Source: BID Type: UNKNOWN 16358 Source: CCN Type: BID-16358 BEA WebLogic Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-0313 Source: XF Type: UNKNOWN weblogic-security-provider-weakness(24298) Source: XF Type: UNKNOWN weblogic-security-provider-weakness(24298) Source: CCN Type: BEA Systems Inc. Security Advisory: (BEA06-116.00) Non-active security provider appears active. | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||