First published: Fri May 19 2006(Updated: )
BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2461 is considered to be a medium security vulnerability due to its potential to expose sensitive information over unencrypted channels.
To fix CVE-2006-2461, upgrade BEA WebLogic Server to version 8.1 Service Pack 4 or later.
The risks associated with CVE-2006-2461 include the possibility of remote attackers intercepting unencrypted sensitive network traffic.
CVE-2006-2461 affects BEA WebLogic Server versions 8.1 and its Service Packs 1, 2, and 3.
CVE-2006-2461 remains a concern for users still running affected versions of WebLogic Server, highlighting the importance of keeping software updated.