CVE-2007-0414: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0414?
CVE-2007-0414 is considered a high severity vulnerability due to its potential to cause a denial of service by hanging the server.
How do I fix CVE-2007-0414?
To fix CVE-2007-0414, upgrade to a version of BEA WebLogic Server that is not affected, specifically versions above 9.0 or apply vendor patches if available.
What versions of BEA WebLogic Server are affected by CVE-2007-0414?
BEA WebLogic Server versions 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 are affected by CVE-2007-0414.
What is the impact of CVE-2007-0414 on my system?
The impact of CVE-2007-0414 is a denial of service that can render the server unresponsive to legitimate requests.
Is there a workaround for CVE-2007-0414?
There is no widely recommended workaround for CVE-2007-0414, and upgrading to a patched version is the suggested approach.