CVE-2005-1744: Critical severity bea weblogic server vulnerability
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1744?
CVE-2005-1744 is rated as a medium severity vulnerability.
How do I fix CVE-2005-1744?
To fix CVE-2005-1744, ensure that users are properly logged out when an application is redeployed.
What versions are affected by CVE-2005-1744?
CVE-2005-1744 affects BEA WebLogic Server and WebLogic Express versions 6.0 through 7.0, including several specific service packs.
Is CVE-2005-1744 publicly known?
Yes, CVE-2005-1744 is a publicly known vulnerability with documented exploits.
What kind of attack does CVE-2005-1744 enable?
CVE-2005-1744 enables unauthorized access to applications due to inadequate user session management after redeployment.