First published: Wed Jan 25 2006(Updated: )
By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0421 is considered a moderate vulnerability due to the potential for unauthorized privilege escalation between web application domains.
To mitigate CVE-2006-0421, it is recommended to restrict the ability to create and manage domains in BEA WebLogic Server to trusted administrators only.
CVE-2006-0421 affects administrators using BEA WebLogic Server versions 6.1 and 7.0 when multiple domains are created on the same machine.
The risks of CVE-2006-0421 include unauthorized access to sensitive data and escalation of privileges across different domains.
CVE-2006-0421 was disclosed in January 2006.