CVE-2006-1351: Medium severity Bea WebLogic Server vulnerability
Published Mar 22, 2006
·Updated
BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal servlet" accessed through HTTP.
Affected Software
8 affected components
Bea WebLogic Server=6.1-sp4
Bea WebLogic Server=6.1-sp5
Bea WebLogic Server=6.1-sp6
Bea WebLogic Server=6.1-sp3
Bea WebLogic Server=6.1-sp1
Bea WebLogic Server=6.1
Bea WebLogic Server=6.1-sp2
Bea WebLogic Server=6.1-sp7
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 22, 2006
CVE Published
01:02 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1351?
CVE-2006-1351 is considered to have a high severity due to its potential for remote file reading by attackers.
2
How do I fix CVE-2006-1351?
To fix CVE-2006-1351, it's recommended to upgrade BEA WebLogic Server to a version later than 6.1 SP7.
3
What versions of WebLogic Server are affected by CVE-2006-1351?
CVE-2006-1351 affects BEA WebLogic Server version 6.1 and all service packs up to SP7.
4
What type of attack does CVE-2006-1351 allow?
CVE-2006-1351 allows remote attackers to read arbitrary files on the server through an internal servlet.
5
Is there a known workaround for CVE-2006-1351?
There are no specific workarounds mentioned for CVE-2006-1351, and upgrading is the advised solution.