WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
BID:17168
Info
WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
| Bugtraq ID: | 17168 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2005 12:00AM |
| Updated: | Mar 21 2006 05:04PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems WebLogic Express for Win32 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 5 |
Discussion
WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
WebLogic Server and WebLogic Express are prone to a weakness facilitating excessive invalid login attempts against a username. This issue can aid in brute-force attacks.
This issue was originally reported in BID 15052 (BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities). Due to the availability of more information, this issue is being assigned a new BID.
WebLogic Server and WebLogic Express are prone to a weakness facilitating excessive invalid login attempts against a username. This issue can aid in brute-force attacks.
This issue was originally reported in BID 15052 (BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities). Due to the availability of more information, this issue is being assigned a new BID.
Exploit / POC
WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
Solution:
The vendor has released an advisory and fixes to address this issue.
BEA Systems WebLogic Express for Win32 7.0 SP 6
BEA Systems WebLogic Server for Win32 7.0 SP 6
BEA Systems Weblogic Server 7.0 SP 6
BEA Systems WebLogic Express 7.0 SP 6
Solution:
The vendor has released an advisory and fixes to address this issue.
BEA Systems WebLogic Express for Win32 7.0 SP 6
-
BEA Systems CR238192_70sp6.jar
ftp://ftpna.beasys.com/pub/releases/security/CR238192_70sp6.jar
BEA Systems WebLogic Server for Win32 7.0 SP 6
-
BEA Systems CR238192_70sp6.jar
ftp://ftpna.beasys.com/pub/releases/security/CR238192_70sp6.jar
BEA Systems Weblogic Server 7.0 SP 6
-
BEA Systems CR238192_70sp6.jar
ftp://ftpna.beasys.com/pub/releases/security/CR238192_70sp6.jar
BEA Systems WebLogic Express 7.0 SP 6
-
BEA Systems CR238192_70sp6.jar
ftp://ftpna.beasys.com/pub/releases/security/CR238192_70sp6.jar
References
WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
References:
References: