CVE-2006-0420: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which allows remote attackers to cause a denial of service (slowdown) via unknown attack vectors that cause "looping stack overflow errors."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0420?
CVE-2006-0420 is classified as a denial of service vulnerability, which can result in a system slowdown.
How do I fix CVE-2006-0420?
To fix CVE-2006-0420, upgrade BEA WebLogic Server to a version that is not affected, typically a post-SP4 release.
What software does CVE-2006-0420 affect?
CVE-2006-0420 affects BEA WebLogic Server and WebLogic Express versions 7.0 SP2 to SP6 and 8.1 through SP4.
What type of vulnerability is CVE-2006-0420?
CVE-2006-0420 is a denial of service vulnerability caused by improper handling of servlet relative forwarding.
Can CVE-2006-0420 lead to complete system compromise?
CVE-2006-0420 does not lead to complete system compromise but can significantly impair application performance.