First published: Sat Dec 31 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4751 is considered to be a high severity vulnerability due to its ability to allow remote attackers to gain administrative privileges.
To fix CVE-2005-4751, upgrade to a patched version of the BEA WebLogic Server or WebLogic Express that addresses the XSS vulnerabilities.
CVE-2005-4751 affects BEA WebLogic Server versions 6.1 SP7 and earlier, 7.0 SP6 and earlier, 8.1 SP4 and earlier, and 9.0.
CVE-2005-4751 exposes multiple cross-site scripting (XSS) vulnerabilities.
Yes, CVE-2005-4751 can potentially lead to data leaks by allowing attackers to execute arbitrary scripts in users' browsers.