CVE-2004-2424: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2424?
CVE-2004-2424 is classified as a denial of service vulnerability.
How do I fix CVE-2004-2424?
To fix CVE-2004-2424, upgrade to a patched version of BEA WebLogic Server or apply the necessary security updates.
What versions of WebLogic Server are affected by CVE-2004-2424?
CVE-2004-2424 affects BEA WebLogic Server and WebLogic Express versions 8.1 through 8.1 SP2.
How does CVE-2004-2424 affect my server's performance?
CVE-2004-2424 can cause network port consumption, leading to a denial of service and impacting server performance.
Can CVE-2004-2424 be exploited remotely?
Yes, CVE-2004-2424 can be exploited by remote attackers, potentially affecting the availability of the server.