First published: Sat Dec 31 2005(Updated: )
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4765 is considered a moderate severity vulnerability according to various security assessments.
To fix CVE-2005-4765, upgrade to a supported version of WebLogic Server that correctly implements the secure t3s protocol.
CVE-2005-4765 affects BEA WebLogic Server versions 8.1 SP4 and earlier and 7.0 SP6 and earlier.
CVE-2005-4765 is a security vulnerability related to network protocol misconfiguration that allows potential unauthorized access.
Yes, CVE-2005-4765 can be exploited remotely by attackers due to the use of the insecure t3 protocol.