First published: Fri Dec 31 2004(Updated: )
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0.0.1-sp4 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0.0.1-sp3 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0.0.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2696 is classified as a high severity vulnerability due to its potential for causing unauthorized access to user identities.
To fix CVE-2004-2696, apply the recommended patches provided by Oracle for the affected versions of WebLogic Server.
CVE-2004-2696 affects Oracle WebLogic Server versions 6.1, 7.0, and 8.1, including various service packs.
Exploiting CVE-2004-2696 may allow an attacker to impersonate another user leading to unauthorized access and actions.
As a workaround for CVE-2004-2696, consider limiting remote access or implementing stricter authentication controls.