First published: Tue Jan 23 2007(Updated: )
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | <=8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | <=6.1 | |
Oracle WebLogic Server | <=7.0 | |
Oracle WebLogic Server | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0414 is considered a high severity vulnerability due to its potential to cause a denial of service by hanging the server.
To fix CVE-2007-0414, upgrade to a version of BEA WebLogic Server that is not affected, specifically versions above 9.0 or apply vendor patches if available.
BEA WebLogic Server versions 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 are affected by CVE-2007-0414.
The impact of CVE-2007-0414 is a denial of service that can render the server unresponsive to legitimate requests.
There is no widely recommended workaround for CVE-2007-0414, and upgrading to a patched version is the suggested approach.