First published: Tue May 24 2005(Updated: )
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =6.0 | |
Oracle WebLogic Server | =6.0 | |
Oracle WebLogic Server | =6.0 | |
Oracle WebLogic Server | =6.0-sp1 | |
Oracle WebLogic Server | =6.0-sp1 | |
Oracle WebLogic Server | =6.0-sp1 | |
Oracle WebLogic Server | =6.0-sp2 | |
Oracle WebLogic Server | =6.0-sp2 | |
Oracle WebLogic Server | =6.0-sp2 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp3 | |
Oracle WebLogic Server | =7.0.0.1-sp3 | |
Oracle WebLogic Server | =7.0.0.1-sp4 | |
Oracle WebLogic Server | =7.0.0.1-sp4 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =8.1-sp4 | |
BEA WebLogic Portal | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-1743 is classified as critical due to its potential impact on security identity management.
To fix CVE-2005-1743, apply the recommended patches and updates provided by BEA for the affected WebLogic Server versions.
CVE-2005-1743 affects BEA WebLogic Server and WebLogic Express versions 6.0 through 8.1, including various service packs.
The risks associated with CVE-2005-1743 include unauthorized access and improper handling of security exceptions, which can compromise security auditing.
While CVE-2005-1743 is an older vulnerability, it remains relevant for organizations using unsupported versions of WebLogic that have not mitigated this issue.