CVE-2005-4754: Medium severity oracle weblogic server vulnerability
Published Dec 31, 2005
·Updated
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation."
Affected Software
8 affected components
Bea WebLogic Server=8.1
Bea WebLogic Server=8.1
Bea WebLogic Server=8.1-sp3
Bea WebLogic Server=8.1-sp1
Bea WebLogic Server=8.1-sp3
Bea WebLogic Server=8.1-sp2
Bea WebLogic Server=8.1-sp1
Bea WebLogic Server=8.1-sp2
Remediation
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Apr 1, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4754?
CVE-2005-4754 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2005-4754?
To mitigate CVE-2005-4754, upgrade to a later version of BEA WebLogic Server that addressed this vulnerability.
3
What type of information can be exposed by CVE-2005-4754?
CVE-2005-4754 can allow remote attackers to obtain sensitive information such as intranet IP addresses.
4
Which versions of BEA WebLogic Server are affected by CVE-2005-4754?
CVE-2005-4754 affects BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier versions.
5
What is the attack vector for CVE-2005-4754?
The attack vector for CVE-2005-4754 involves unknown methods related to network address translation.