CVE-2005-4705: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4705?
CVE-2005-4705 has a medium severity level due to its potential for remote exploitation.
How do I fix CVE-2005-4705?
To fix CVE-2005-4705, upgrade to a patched version of Oracle WebLogic Server that addresses this vulnerability.
What versions of WebLogic Server are affected by CVE-2005-4705?
CVE-2005-4705 affects WebLogic Server versions 6.1 SP1-SP7, 7.0 SP1-SP6, and 8.1 SP1-SP4.
Can exploitation of CVE-2005-4705 lead to data loss?
Yes, exploitation of CVE-2005-4705 can allow attackers to sniff sensitive data, potentially leading to data loss.
Is there a recommended mitigation for CVE-2005-4705?
In addition to upgrading, a recommended mitigation for CVE-2005-4705 is to enforce secure protocols for all connections to the server.