First published: Sat Dec 31 2005(Updated: )
HTTP request smuggling vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allows remote attackers to inject arbitrary HTTP headers via unspecified attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4749 is classified as a significant vulnerability, allowing for HTTP request smuggling.
To fix CVE-2005-4749, upgrade your BEA WebLogic Server to a version that is not affected by this vulnerability.
CVE-2005-4749 affects BEA WebLogic Server versions 6.1 SP7 and earlier, 7.0 SP6 and earlier, and 8.1 SP4 and earlier.
Yes, CVE-2005-4749 can allow attackers to inject arbitrary HTTP headers, potentially leading to unauthorized access.
CVE-2005-4749 is classified as a remote vulnerability, meaning it can be exploited remotely without physical access.