CVE-2005-4760: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4760?
CVE-2005-4760 is considered a high-severity vulnerability due to the potential impact on authorization mechanisms.
How do I fix CVE-2005-4760?
To remediate CVE-2005-4760, it is recommended to upgrade to a patched version of BEA WebLogic Server beyond the affected versions.
What versions are affected by CVE-2005-4760?
CVE-2005-4760 affects BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier, as well as 8.1 SP3 and earlier.
What is the impact of CVE-2005-4760?
The impact of CVE-2005-4760 can lead to unauthorized access if the failure in authorization is not handled properly.
Is CVE-2005-4760 exploitable remotely?
Yes, CVE-2005-4760 is potentially exploitable remotely, allowing attackers to bypass authorization safeguards.