{"api_version":"1","generated_at":"2026-07-24T17:16:59+00:00","cve":"CVE-2006-2470","urls":{"html":"https://cve.report/CVE-2006-2470","api":"https://cve.report/api/cve/CVE-2006-2470.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2470","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2470"},"summary":{"title":"CVE-2006-2470","description":"Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-05-19 10:02:00","updated_at":"2017-07-20 01:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://dev2dev.bea.com/pub/advisory/188","name":"BEA06-126.00","refsource":"BEA","tags":["Patch","Vendor Advisory"],"title":"Console incorrectly set JDBC policies","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26464","name":"weblogic-custom-jdbc-insecure(26464)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1828","name":"ADV-2006-1828","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20130","name":"20130","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"BEA WebLogic Server/Express Multiple Security Issues - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2470","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2470","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2470","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2470","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2470","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20130","refsource":"SECUNIA","url":"http://secunia.com/advisories/20130"},{"name":"ADV-2006-1828","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1828"},{"name":"weblogic-custom-jdbc-insecure(26464)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26464"},{"name":"BEA06-126.00","refsource":"BEA","url":"http://dev2dev.bea.com/pub/advisory/188"}]}},"nvd":{"publishedDate":"2006-05-19 10:02:00","lastModifiedDate":"2017-07-20 01:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2470","Ordinal":"17782","Title":"CVE-2006-2470","CVE":"CVE-2006-2470","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2470","Ordinal":"1","NoteData":"Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2470","Ordinal":"2","NoteData":"2006-05-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2470","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}