CVE-2007-0411: Medium severity Bea WebLogic Server vulnerability
Published Jan 23, 2007
·Updated
BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.
Affected Software
5 affected components
Bea WebLogic Server<=8.1
Bea WebLogic Server=8.1
Bea WebLogic Server=9.0
Bea WebLogic Server=9.1
Bea WebLogic Server=9.2-ga
Remediation
Patch Available
Event History
Jan 23, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0411?
CVE-2007-0411 is considered a high-severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2007-0411?
To fix CVE-2007-0411, apply the latest security patches provided by Oracle for the affected versions of WebLogic Server.
3
Which versions of WebLogic Server are affected by CVE-2007-0411?
CVE-2007-0411 affects BEA WebLogic Server versions 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold.
4
What type of attack can be executed due to CVE-2007-0411?
CVE-2007-0411 allows remote attackers to conduct a man-in-the-middle (MITM) attack.
5
What is the cause of the vulnerability in CVE-2007-0411?
The vulnerability in CVE-2007-0411 is due to improper validation of certificates when WS-Security is used.