Secunia Logo
 
CVE Reference: CVE-2005-1746
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-1746

Description:
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.

CVE Status:
Candidate

References:

ST
  1014049

SAID
  Secunia Advisory: SA15486

BID
  13717

BEA
  http://dev2dev.bea.com/pub/advisory/129


Return to the previous page.