CVE-2007-2695: Medium severity Bea WebLogic Server vulnerability
The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," which allows remote attackers to access administrative data or functionality.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2695?
CVE-2007-2695 is considered to have a critical severity due to the potential for unauthorized access to administrative functions.
How do I fix CVE-2007-2695?
To fix CVE-2007-2695, update your BEA WebLogic Server to a version that has patched this vulnerability.
What versions of WebLogic are affected by CVE-2007-2695?
CVE-2007-2695 affects BEA WebLogic Server versions 6.1 through 9.1 with certain service packs.
Can CVE-2007-2695 be exploited remotely?
Yes, CVE-2007-2695 can be exploited remotely by attackers if the vulnerable WebLogic Server instance is exposed.
What type of attacks could be executed via CVE-2007-2695?
Exploiting CVE-2007-2695 could allow attackers to access sensitive administrative functionalities, leading to potential data breaches.