CVE-2007-0408: High severity Bea WebLogic Server vulnerability
Published Jan 23, 2007
·Updated
BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.
Affected Software
2 affected components
Bea WebLogic Server=8.1
Bea WebLogic Server<=8.1
Remediation
Patch Available
Event History
Jan 23, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0408?
The severity of CVE-2007-0408 is considered high due to improper client certificate validation.
2
How do I fix CVE-2007-0408?
To fix CVE-2007-0408, update your BEA WebLogic Server to a version that addresses this vulnerability.
3
Who is affected by CVE-2007-0408?
CVE-2007-0408 affects users of BEA WebLogic Server 8.1 through 8.1 SP4.
4
What type of attack does CVE-2007-0408 enable?
CVE-2007-0408 enables remote attackers to gain unauthorized access using untrusted X.509 certificates.
5
Is there any workaround for CVE-2007-0408?
No specific workarounds are recommended for CVE-2007-0408; the best solution is to apply the available updates.