CVE-2007-0420: Medium severity Bea WebLogic Server vulnerability
Published Jan 23, 2007
·Updated
BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.
Affected Software
3 affected components
Bea WebLogic Server=9.0
Bea WebLogic Server=9.1
Bea WebLogic Server=9.2-ga
Remediation
Patch Available
Event History
Jan 23, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0420?
CVE-2007-0420 is considered to be of medium severity due to its potential to expose sensitive information.
2
How do I fix CVE-2007-0420?
To fix CVE-2007-0420, upgrade to a patched version of BEA WebLogic Server beyond 9.2 GA.
3
What are the affected versions in CVE-2007-0420?
CVE-2007-0420 affects BEA WebLogic Server versions 9.0, 9.1, and 9.2 GA.
4
What type of attack does CVE-2007-0420 represent?
CVE-2007-0420 represents a remote information disclosure vulnerability due to malformed HTTP requests.
5
Can CVE-2007-0420 be exploited by unauthenticated users?
Yes, CVE-2007-0420 can be exploited by unauthenticated remote attackers.