CVE-2006-0432: Low severity Bea WebLogic Server vulnerability
Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0432?
CVE-2006-0432 is classified as a medium severity vulnerability due to its impact on JNDI resource protection.
How do I fix CVE-2006-0432?
To fix CVE-2006-0432, update the BEA WebLogic Server and WebLogic Express to the latest version that addresses this vulnerability.
What systems are affected by CVE-2006-0432?
CVE-2006-0432 affects BEA WebLogic Server and WebLogic Express version 9.0.
What is the cause of the CVE-2006-0432 vulnerability?
The cause of CVE-2006-0432 is an issue with incorrect security policies being created through the WebLogic Administration Console.
Can CVE-2006-0432 be exploited remotely?
Yes, CVE-2006-0432 can potentially be exploited remotely if the affected WebLogic Server is accessible over a network.