The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic...
Vulnerability Description
The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," which allows remote attackers to access administrative data or functionality.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2695
Credits & Attribution
No credits recorded in the NVD database.
References
- http://dev2dev.bea.com/pub/advisory/274
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34282
- http://securitytracker.com/id?1018057
- http://secunia.com/advisories/25284
- http://secunia.com/advisories/29041
- http://osvdb.org/36074
- http://dev2dev.bea.com/pub/advisory/227
- http://www.vupen.com/english/advisories/2008/0612/references
- http://www.vupen.com/english/advisories/2007/1815
More from bea
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.