CVE-2007-2697: Medium severity Bea WebLogic Server vulnerability
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2697?
CVE-2007-2697 has a medium severity rating due to the potential for brute-force attacks against the embedded LDAP server.
How do I fix CVE-2007-2697?
To fix CVE-2007-2697, implement proper authentication attempt limits and auditing within your WebLogic configurations.
Which versions are affected by CVE-2007-2697?
CVE-2007-2697 affects BEA WebLogic Express and WebLogic Server versions 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1.
Can CVE-2007-2697 lead to unauthorized access?
Yes, CVE-2007-2697 can lead to unauthorized access if attackers exploit the lack of authentication attempt limits.
What should I monitor to mitigate CVE-2007-2697?
You should monitor authentication logs for unusual activity to mitigate the risks associated with CVE-2007-2697.