First published: Fri May 19 2006(Updated: )
The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2468 is classified as a medium severity vulnerability.
To fix CVE-2006-2468, update to a patched version of BEA WebLogic Server or disable the display of the domain name in the login form.
CVE-2006-2468 affects BEA WebLogic Server versions 7.0 up to SP6 and 8.1 up to SP4.
CVE-2006-2468 allows remote attackers to gain sensitive information by observing the domain name in the login form.
Yes, CVE-2006-2468 can be exploited remotely by attackers with network access to the WebLogic Server Administration Console.