CVE-2007-2704: Medium severity Bea WebLogic Server vulnerability
Published May 16, 2007
·Updated
BEA WebLogic Server 9.0 through 9.2 allows remote attackers to cause a denial of service (SSL port unavailability) by accessing a half-closed SSL socket.
Affected Software
3 affected components
Bea WebLogic Server=9.0
Bea WebLogic Server=9.2
Bea WebLogic Server=9.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2704?
CVE-2007-2704 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-2704?
To fix CVE-2007-2704, upgrade to a patched version of BEA WebLogic Server that is not affected, such as versions 9.2 or later.
3
What versions of WebLogic Server are affected by CVE-2007-2704?
CVE-2007-2704 affects BEA WebLogic Server versions 9.0, 9.1, and 9.2.
4
What type of attack does CVE-2007-2704 facilitate?
CVE-2007-2704 allows remote attackers to cause a denial of service by exploiting a half-closed SSL socket.
5
Can CVE-2007-2704 be exploited remotely?
Yes, CVE-2007-2704 can be exploited remotely by attackers.