CVE-2007-0411Weblogic Server vulnerability

4 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
1.0%
top 22.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23
Latest updateMay 1

Description

BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rf28-cqjh-x6j8: BEA WebLogic Server 82022-05-01
CVEList
CVE-2007-0411: BEA WebLogic Server 82007-01-23

💥Exploits & PoCs

1
Exploit-DB
Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow2008-02-27
CVE-2007-0411 — BEA Weblogic Server vulnerability | cvebase