CVE-2005-1748: Medium severity Bea WebLogic Server vulnerability
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1748?
CVE-2005-1748 is considered a medium severity vulnerability that could allow unauthorized access to user data.
How do I fix CVE-2005-1748?
To fix CVE-2005-1748, ensure that anonymous binds are disabled on the embedded LDAP server in affected versions of BEA WebLogic Server.
Which versions of BEA WebLogic Server are affected by CVE-2005-1748?
CVE-2005-1748 affects BEA WebLogic Server versions 6.0, 7.0, and 8.1 up to Service Pack 4.
What kind of attacks can exploit CVE-2005-1748?
CVE-2005-1748 can be exploited to view user entries or may lead to a denial of service.
Is there a patch available for CVE-2005-1748?
Yes, a patch is available that disables anonymous binds for the affected versions of BEA WebLogic Server.