CVE-2006-0425: Medium severity Oracle Weblogic Portal vulnerability
Published Jan 25, 2006
·Updated
BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.
Affected Software
4 affected components
Oracle Weblogic Portal=8.1
Oracle Weblogic Portal=8.1-sp1
Oracle Weblogic Portal=8.1-sp2
Oracle Weblogic Portal=8.1-sp3
Remediation
Patch Available
Patch Available
Event History
Jan 25, 2006
CVE Published
11:07 PM
Jan 26, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0425?
CVE-2006-0425 is classified as having a moderate severity level due to its ability to expose sensitive information.
2
How do I fix CVE-2006-0425?
To remediate CVE-2006-0425, it is recommended to upgrade to a patched version of BEA WebLogic Portal beyond SP4.
3
Who is affected by CVE-2006-0425?
CVE-2006-0425 affects users of BEA WebLogic Portal versions 8.1 through SP4.
4
What kind of vulnerability is CVE-2006-0425?
CVE-2006-0425 is an information disclosure vulnerability, allowing unauthorized access to deployment descriptor files.
5
Are there any known exploits for CVE-2006-0425?
Yes, CVE-2006-0425 has been reported to have potential exploits that could allow attackers to retrieve sensitive data.