CVE-2004-2320: Infoleak
The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2320?
CVE-2004-2320 is classified as a medium-severity vulnerability that can lead to information exposure via cross-site tracing attacks.
How do I fix CVE-2004-2320?
To mitigate CVE-2004-2320, configure the BEA WebLogic Server to disable the HTTP TRACE method in the server settings.
Which versions of Oracle WebLogic Server are affected by CVE-2004-2320?
CVE-2004-2320 affects multiple versions of Oracle WebLogic Server, including versions 5.1 through 8.1 SP2.
What type of attacks can exploit CVE-2004-2320?
CVE-2004-2320 can be exploited through cross-site tracing (XST) attacks, which can steal sensitive information from users.
Is there a patch available for CVE-2004-2320?
Yes, Oracle provides updates and patches to address CVE-2004-2320, and users should apply the latest security updates.