Vulnerability Name: CVE-2007-0410 (CCN-31561) Assigned: 2007-01-16 Published: 2007-01-16 Updated: 2018-10-17 Summary: Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events." CVSS v3 Severity: 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2007-0410 Source: BEA Type: Patch, Vendor AdvisoryBEA07-137.00 Source: OSVDB Type: Broken Link38502 Source: CCN Type: SA23750BEA WebLogic Multiple Vulnerabilities and Security Issues Source: SECUNIA Type: Third Party Advisory23750 Source: CCN Type: SECTRACK ID: 1017525WebLogic Bugs Let Remote Users Gain Access, Obtain Information, and Deny Service Source: SECTRACK Type: Third Party Advisory, VDB Entry1017525 Source: CCN Type: OSVDB ID: 38502BEA WebLogic Thread Management T3 Authentication Unspecified Remote DoS Source: BID Type: Third Party Advisory, VDB Entry22082 Source: CCN Type: BID-22082BEA Multiple Products Multiple Vulnerabilities Source: VUPEN Type: Third Party AdvisoryADV-2007-0213 Source: XF Type: UNKNOWNweblogic-t3-dos(31561) Source: CCN Type: BEA07-137.00Incorrect thread management may lead to server unavailability. Vulnerable Configuration: Configuration 1 :cpe:/a:bea:weblogic_server:7.0:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:9.0:*:*:*:*:*:*:* OR cpe:/a:bea:weblogic_server:9.1:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:weblogic_server:9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:9.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
bea weblogic server 7.0
bea weblogic server 7.0 sp1
bea weblogic server 7.0 sp2
bea weblogic server 7.0 sp3
bea weblogic server 7.0 sp4
bea weblogic server 7.0 sp5
bea weblogic server 7.0 sp6
bea weblogic server 8.1
bea weblogic server 8.1 sp1
bea weblogic server 8.1 sp2
bea weblogic server 8.1 sp3
bea weblogic server 8.1 sp4
bea weblogic server 8.1 sp5
bea weblogic server 9.0
bea weblogic server 9.1
oracle weblogic server 9.0
oracle weblogic server 9.1