First published: Wed May 16 2007(Updated: )
The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," which allows remote attackers to access administrative data or functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =7.0-sp7 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =8.1-sp5 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =8.1-sp5 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =9.1-ga | |
Oracle WebLogic Server | =7.0-sp7 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =9.1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2695 is considered to have a critical severity due to the potential for unauthorized access to administrative functions.
To fix CVE-2007-2695, update your BEA WebLogic Server to a version that has patched this vulnerability.
CVE-2007-2695 affects BEA WebLogic Server versions 6.1 through 9.1 with certain service packs.
Yes, CVE-2007-2695 can be exploited remotely by attackers if the vulnerable WebLogic Server instance is exposed.
Exploiting CVE-2007-2695 could allow attackers to access sensitive administrative functionalities, leading to potential data breaches.