CVE-2004-2320
Summary
| CVE | CVE-2004-2320 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Server | 5.1 | All | express | All |
| Application | Bea | Weblogic Server | 5.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp10 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp10 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp10 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp11 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp11 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp11 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp12 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp12 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp12 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp13 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp13 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp13 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp3 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp3 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp3 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp4 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp4 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp4 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp5 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp5 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp5 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp6 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp6 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp6 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp7 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp7 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp7 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp8 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp8 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp8 | win32 | All |
| Application | Bea | Weblogic Server | 5.1 | sp9 | All | All |
| Application | Bea | Weblogic Server | 5.1 | sp9 | express | All |
| Application | Bea | Weblogic Server | 5.1 | sp9 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | All | All | All |
| Application | Bea | Weblogic Server | 6.1 | All | express | All |
| Application | Bea | Weblogic Server | 6.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp3 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp3 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp3 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp4 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp4 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp4 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp5 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp5 | express | All |
| Application | Bea | Weblogic Server | 6.1 | sp5 | win32 | All |
| Application | Bea | Weblogic Server | 6.1 | sp6 | All | All |
| Application | Bea | Weblogic Server | 6.1 | sp6 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | All | All | All |
| Application | Bea | Weblogic Server | 7.0 | All | express | All |
| Application | Bea | Weblogic Server | 7.0 | All | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | All | All | All |
| Application | Bea | Weblogic Server | 8.1 | All | express | All |
| Application | Bea | Weblogic Server | 8.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | win32 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#867593 - Web servers enable HTTP TRACE method by default | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| www.osvdb.org/3726 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - BEA WebLogic HTTP TRACE Response Cross-Site Scripting Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| WebLogic Server and Express HTTP TRACE Credential Theft Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| SecurityTracker.com Archives - WebLogic Server and Express Input Validation Flaw in Processing HTTP TRACE Requests Permits Cross-Site Scripting | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Patch |
| Patches available to prevent compromise of user accounts | af854a3a-2127-422b-91ae-364da2661108 | dev2dev.bea.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-03-05 | Joshua Bressers | The Apache Software Foundation do not treat this as a security issue. A configuration change can be made to disable the ability to respond to HTTP TRACE requests if required. For more information please see: http://www.apacheweek.com/issues/03-01-24#news |