CVE-2005-4765: High severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4765?
CVE-2005-4765 is considered a moderate severity vulnerability according to various security assessments.
How do I fix CVE-2005-4765?
To fix CVE-2005-4765, upgrade to a supported version of WebLogic Server that correctly implements the secure t3s protocol.
Which versions of WebLogic Server are affected by CVE-2005-4765?
CVE-2005-4765 affects BEA WebLogic Server versions 8.1 SP4 and earlier and 7.0 SP6 and earlier.
What type of vulnerability is CVE-2005-4765?
CVE-2005-4765 is a security vulnerability related to network protocol misconfiguration that allows potential unauthorized access.
Is remote exploitation possible with CVE-2005-4765?
Yes, CVE-2005-4765 can be exploited remotely by attackers due to the use of the insecure t3 protocol.