First published: Wed Jan 25 2006(Updated: )
Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =9.0-sp1 | |
Oracle WebLogic Server | =9.0-sp1 | |
Oracle WebLogic Server | =9.0-sp2 | |
Oracle WebLogic Server | =9.0-sp2 | |
Oracle WebLogic Server | =9.0-sp3 | |
Oracle WebLogic Server | =9.0-sp3 | |
Oracle WebLogic Server | =9.0-sp4 | |
Oracle WebLogic Server | =9.0-sp4 | |
Oracle WebLogic Server | =9.0-sp5 | |
Oracle WebLogic Server | =9.0-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0430 has been identified as a denial of service vulnerability that can significantly affect server performance.
To mitigate CVE-2006-0430, it is recommended to review and adjust the connection filter configurations in affected versions of BEA WebLogic Server.
CVE-2006-0430 impacts BEA WebLogic Server versions 7.0 through SP6, 8.1 through SP5, and 9.0.
Yes, attackers can exploit CVE-2006-0430 to induce server slowdown, resulting in a denial of service.
The main impact of CVE-2006-0430 is a potential denial of service due to degraded server performance when connection filters are enabled.