CVE-2006-0432Weblogic Server vulnerability

3 documents3 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 71.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 25
Latest updateMay 1

Description

Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m4wr-7hxh-rfv4: Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 92022-05-01
CVEList
CVE-2006-0432: Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 92006-01-25
CVE-2006-0432 — BEA Weblogic Server vulnerability | cvebase