First published: Sat Dec 31 2005(Updated: )
Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed through HTTP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4758 has been classified as a high severity vulnerability due to its potential impact on sensitive data.
To mitigate CVE-2005-4758, it is recommended to upgrade to a newer version of BEA WebLogic Server after applying the necessary patches.
CVE-2005-4758 affects users of BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier versions.
The implications of CVE-2005-4758 include the risk of unauthorized access to sensitive files by remote authenticated users.
CVE-2005-4758 involves the Administration server in BEA WebLogic Server and WebLogic Express, specifically through an internal servlet accessed via HTTP.