BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
BID:12548
Info
BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
| Bugtraq ID: | 12548 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2005 12:00AM |
| Updated: | Feb 14 2005 12:00AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
A remote information disclosure weakness affects WebLogic Server and WebLogic Express. This issue is due to a failure of the application to present authentication failures securely.
This issue may allow an attacker to use the revealed information to carry out successful brute fore password attacks against an affected application.
A remote information disclosure weakness affects WebLogic Server and WebLogic Express. This issue is due to a failure of the application to present authentication failures securely.
This issue may allow an attacker to use the revealed information to carry out successful brute fore password attacks against an affected application.
Exploit / POC
BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
Solution:
The vendor has released advisory BEA05-74.00 along with service pack 4 for WebLogic Server 8.1 and a patch for WebLogic Server 7.0 service pack 5 dealing with this issue. Please contact the vendor for information on attaining service pack 4 for WebLogic.
The vendor has released advisory BEA05-74.01 dealing with this issue. This advisory is an update to BEA05-74.00. Service pack 4 for WebLogic Server 8.1, and service pack 5 and 6 for WebLogic Server 7.0 are also considered vulnerable.
The vendor states that WebLogic Server 8.1 Service Pack 5, and WebLogic Server 7.0 Service Pack 7 will contain fixes for this issue. Until then, please see the new advisory for information on obtaining fixes.
Users are advised to disregard advisory BEA05-74.00, and should review the new one for further information.
Solution:
The vendor has released advisory BEA05-74.00 along with service pack 4 for WebLogic Server 8.1 and a patch for WebLogic Server 7.0 service pack 5 dealing with this issue. Please contact the vendor for information on attaining service pack 4 for WebLogic.
The vendor has released advisory BEA05-74.01 dealing with this issue. This advisory is an update to BEA05-74.00. Service pack 4 for WebLogic Server 8.1, and service pack 5 and 6 for WebLogic Server 7.0 are also considered vulnerable.
The vendor states that WebLogic Server 8.1 Service Pack 5, and WebLogic Server 7.0 Service Pack 7 will contain fixes for this issue. Until then, please see the new advisory for information on obtaining fixes.
Users are advised to disregard advisory BEA05-74.00, and should review the new one for further information.
References
BEA WebLogic Server And WebLogic Express Authentication Failure Information Disclosure Weakness
References:
References:
- Security Advisory: (BEA05-74.00) - Login exceptions give clues to failure (BEA Systems)
- Security Advisory: (BEA05-74.01) (BEA Systems)
- Weblogic (BEA Systems)
- WebLogic Server Product Homepage (Oracle)