Vulnerability Name: CVE-2006-2472 (CCN-26466) Assigned: 2006-05-15 Published: 2006-05-15 Updated: 2017-07-20 Summary: Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys. Hyperlink #907650 has patches for the following products:
WebLogic Server 9.1
WebLogic Server 9.0
This vulnerability is addressed in the following product releases:
BEA Systems, Weblogic Server, 8.1 SP 6
BEA Systems, Weblogic Express, 8.1 SP 6
BEA Systems, Weblogic Server, 7.0 SP 7
BEA Systems, Weblogic Express, 7.0 SP 7
BEA Systems, Weblogic Server, 6.1 SP 8
BEA Systems, Weblogic Express, 6.1 SP 8 CVSS v3 Severity: 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): NoneAvailibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-Other Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2006-2472 Source: BEA Type: Patch, Vendor AdvisoryBEA06-124.00 Source: CCN Type: SA20130BEA WebLogic Server/Express Multiple Security Issues Source: SECUNIA Type: Patch, Vendor Advisory20130 Source: CCN Type: SECTRACK ID: 1016095WebLogic Server May Let Applications Obtain Private Keys Source: SECTRACK Type: UNKNOWN1016095 Source: CCN Type: OSVDB ID: 25552BEA WebLogic Untrusted Application Private Key Disclosure Source: CCN Type: BID-17982BEA WebLogic Multiple Vulnerabilities Source: VUPEN Type: UNKNOWNADV-2006-1828 Source: XF Type: UNKNOWNweblogic-private-key-disclosure(26466) Source: XF Type: UNKNOWNweblogic-private-key-disclosure(26466) Source: CCN Type: BEA Systems Inc. Security Advisory: (BEA06-124.00)Applications installed on WebLogic Server can obtain private keys Vulnerable Configuration: Configuration 1 :cpe:/a:bea:weblogic_server:6.1:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:*:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp6:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:6.1:sp7:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:*:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:*:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:* OR cpe:/a:bea:weblogic_server:9.0:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:9.1:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:weblogic_server:9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:9.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
bea weblogic server 6.1
bea weblogic server 6.1
bea weblogic server 6.1 sp1
bea weblogic server 6.1 sp1
bea weblogic server 6.1 sp2
bea weblogic server 6.1 sp2
bea weblogic server 6.1 sp3
bea weblogic server 6.1 sp3
bea weblogic server 6.1 sp4
bea weblogic server 6.1 sp4
bea weblogic server 6.1 sp5
bea weblogic server 6.1 sp5
bea weblogic server 6.1 sp6
bea weblogic server 6.1 sp6
bea weblogic server 6.1 sp7
bea weblogic server 6.1 sp7
bea weblogic server 7.0
bea weblogic server 7.0
bea weblogic server 7.0 sp1
bea weblogic server 7.0 sp1
bea weblogic server 7.0 sp2
bea weblogic server 7.0 sp2
bea weblogic server 7.0 sp3
bea weblogic server 7.0 sp3
bea weblogic server 7.0 sp4
bea weblogic server 7.0 sp4
bea weblogic server 7.0 sp5
bea weblogic server 7.0 sp5
bea weblogic server 7.0 sp6
bea weblogic server 7.0 sp6
bea weblogic server 8.1
bea weblogic server 8.1
bea weblogic server 8.1 sp1
bea weblogic server 8.1 sp1
bea weblogic server 8.1 sp2
bea weblogic server 8.1 sp2
bea weblogic server 8.1 sp3
bea weblogic server 8.1 sp3
bea weblogic server 8.1 sp4
bea weblogic server 8.1 sp4
bea weblogic server 8.1 sp5
bea weblogic server 8.1 sp5
bea weblogic server 9.0
bea weblogic server 9.1
oracle weblogic server 9.0
oracle weblogic server 9.1