CVE-2008-0901: Infoleak
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0901?
CVE-2008-0901 is considered to have a medium severity rating due to its potential for remote exploitation.
How do I fix CVE-2008-0901?
To fix CVE-2008-0901, apply the latest patches or updates provided by Oracle for affected versions of WebLogic Server.
Is CVE-2008-0901 exploitable remotely?
Yes, CVE-2008-0901 can be exploited remotely by attackers through crafted URLs.
What versions of WebLogic Server are affected by CVE-2008-0901?
CVE-2008-0901 affects BEA WebLogic Server and Express versions from 7.0 through 10.0.
Can account lockout prevent exploitation of CVE-2008-0901?
No, even when account lockout is activated, CVE-2008-0901 allows attackers to conduct brute force password guessing attacks.