First published: Tue Jan 23 2007(Updated: )
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =8.1-sp5 | |
Oracle WebLogic Server | =9.1 | |
Oracle WebLogic Server | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0417 has a critical severity level due to the potential for unauthorized administrative access.
To fix CVE-2007-0417, apply the latest patches provided by Oracle for your specific version of WebLogic Server.
CVE-2007-0417 affects BEA WebLogic Server versions 7.0 to 9.1, including specific service packs.
Attackers can exploit CVE-2007-0417 to perform unauthorized EJB container persistence operations with an administrative identity.
Yes, public exploits for CVE-2007-0417 have been reported, emphasizing the need for immediate mitigation.