CVE-2007-0408 Information

Description

BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections which allows remote attackers to obtain access via an untrusted X.509 certificate.

Reference

http://dev2dev.bea.com/pub/advisory/202 http://osvdb.org/38500 http://secunia.com/advisories/23750 http://securitytracker.com/id?1017519 http://www.securityfocus.com/bid/22082 http://www.vupen.com/english/advisories/2007/0213

Share on: