CVE-2005-1746: Medium severity bea weblogic server vulnerability
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1746?
CVE-2005-1746 has been assigned a moderate severity due to the potential for a denial of service through cluster slowdown.
How do I fix CVE-2005-1746?
To fix CVE-2005-1746, update to the latest patched version of Oracle WebLogic Server that addresses this vulnerability.
What versions of WebLogic Server are affected by CVE-2005-1746?
WebLogic Server versions 6.0 through 8.1 are affected by CVE-2005-1746.
Can CVE-2005-1746 be exploited remotely?
Yes, CVE-2005-1746 can be exploited remotely if an attacker sends a specially crafted cookie.
What is the impact of CVE-2005-1746 on a WebLogic cluster?
The impact of CVE-2005-1746 on a WebLogic cluster is a potential slowdown, leading to denial of service.