First published: Fri Dec 31 2004(Updated: )
The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =5.1-sp8 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =5.1-sp11 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =5.1-sp7 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =5.1-sp8 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =5.1-sp3 | |
Oracle WebLogic Server | =5.1-sp2 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =5.1-sp2 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =5.1-sp5 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =5.1-sp5 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =5.1-sp12 | |
Oracle WebLogic Server | =5.1-sp11 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =5.1-sp1 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =5.1-sp6 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =5.1-sp12 | |
Oracle WebLogic Server | =5.1-sp6 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =5.1-sp9 | |
Oracle WebLogic Server | =5.1-sp1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =5.1-sp4 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =5.1-sp11 | |
Oracle WebLogic Server | =5.1-sp7 | |
Oracle WebLogic Server | =5.1-sp3 | |
Oracle WebLogic Server | =5.1-sp8 | |
Oracle WebLogic Server | =5.1-sp9 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =5.1-sp13 | |
Oracle WebLogic Server | =5.1-sp10 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =5.1-sp3 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =5.1-sp5 | |
Oracle WebLogic Server | =5.1-sp9 | |
Oracle WebLogic Server | =5.1 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =5.1-sp12 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =5.1-sp1 | |
Oracle WebLogic Server | =5.1-sp13 | |
Oracle WebLogic Server | =5.1 | |
Oracle WebLogic Server | =5.1-sp6 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =5.1-sp4 | |
Oracle WebLogic Server | =5.1-sp13 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =5.1-sp10 | |
Oracle WebLogic Server | =5.1-sp10 | |
Oracle WebLogic Server | =5.1-sp7 | |
Oracle WebLogic Server | =5.1-sp4 | |
Oracle WebLogic Server | =5.1-sp2 | |
Oracle WebLogic Server | =7.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2320 is classified as a medium-severity vulnerability that can lead to information exposure via cross-site tracing attacks.
To mitigate CVE-2004-2320, configure the BEA WebLogic Server to disable the HTTP TRACE method in the server settings.
CVE-2004-2320 affects multiple versions of Oracle WebLogic Server, including versions 5.1 through 8.1 SP2.
CVE-2004-2320 can be exploited through cross-site tracing (XST) attacks, which can steal sensitive information from users.
Yes, Oracle provides updates and patches to address CVE-2004-2320, and users should apply the latest security updates.