Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-2697
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2697

Description:
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/34291

ST
  1018057

SAID
  Secunia Advisory: SA25284

BEA
  http://dev2dev.bea.com/pub/advisory/229


Return to the previous page.