CVE-2004-0711: High severity Bea WebLogic Server vulnerability
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "" as wildcards as if they were the legal "/" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0711?
CVE-2004-0711 is classified as a medium severity vulnerability.
How does CVE-2004-0711 affect BEA WebLogic Server?
CVE-2004-0711 allows remote attackers to bypass intended access restrictions due to improper handling of wildcard patterns.
What versions of WebLogic Server are affected by CVE-2004-0711?
CVE-2004-0711 affects BEA WebLogic Server versions 6.x and 7.x.
How can I remediate the vulnerability CVE-2004-0711?
To remediate CVE-2004-0711, it is recommended to upgrade to a patched version of BEA WebLogic Server.
Is there a workaround for CVE-2004-0711?
While proper configuration could potentially mitigate CVE-2004-0711, upgrading to a secure version is the most reliable approach.