CVE-2005-4749: Medium severity Bea WebLogic Server vulnerability
HTTP request smuggling vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allows remote attackers to inject arbitrary HTTP headers via unspecified attack vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4749?
CVE-2005-4749 is classified as a significant vulnerability, allowing for HTTP request smuggling.
How do I fix CVE-2005-4749?
To fix CVE-2005-4749, upgrade your BEA WebLogic Server to a version that is not affected by this vulnerability.
Which versions of WebLogic Server are affected by CVE-2005-4749?
CVE-2005-4749 affects BEA WebLogic Server versions 6.1 SP7 and earlier, 7.0 SP6 and earlier, and 8.1 SP4 and earlier.
Can CVE-2005-4749 lead to unauthorized access?
Yes, CVE-2005-4749 can allow attackers to inject arbitrary HTTP headers, potentially leading to unauthorized access.
Is CVE-2005-4749 a local or remote vulnerability?
CVE-2005-4749 is classified as a remote vulnerability, meaning it can be exploited remotely without physical access.