CVE-2005-4764: High severity oracle weblogic server vulnerability
BEA WebLogic Server and WebLogic Express 9.0, 8.1, and 7.0 lock out the admin user account after multiple incorrect password guesses, which allows remote attackers who know or guess the admin account name to cause a denial of service (blocked admin logins).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4764?
CVE-2005-4764 is considered to have a medium severity level due to its potential to cause a denial of service.
How do I fix CVE-2005-4764?
To mitigate CVE-2005-4764, ensure you have updated to a patched version of Oracle WebLogic Server that addresses this vulnerability.
What versions of WebLogic Server are affected by CVE-2005-4764?
CVE-2005-4764 affects Oracle WebLogic Server versions 7.0, 8.1, and various service packs of these versions.
What is the impact of CVE-2005-4764 on my WebLogic Server?
The impact of CVE-2005-4764 is that it can lock out the administrator account after multiple failed login attempts, leading to a denial of service.
Is there a workaround for CVE-2005-4764?
A potential workaround for CVE-2005-4764 is to implement account lockout policies or access controls to limit exposure.