First published: Wed Jan 25 2006(Updated: )
BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0429 has a moderate severity level due to potential security misconfigurations by administrators.
To fix CVE-2006-0429, ensure that all security providers are correctly configured and activated after a server reboot.
CVE-2006-0429 affects BEA WebLogic Server and WebLogic Express version 9.0.
CVE-2006-0429 is a security misconfiguration vulnerability that can lead to inappropriate administrative actions.
CVE-2006-0429 primarily requires local administrative access to exploit due to its nature of affecting security configurations.