CVE-2007-2695 Information

Description

The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7 7.0 through SP7 8.1 through SP5 9.0 and 9.1 when SecureProxy is enabled may process \external requests on behalf of a system identity\ which allows remote attackers to access administrative data or functionality.

Reference

http://dev2dev.bea.com/pub/advisory/227 http://dev2dev.bea.com/pub/advisory/274 http://osvdb.org/36074 http://secunia.com/advisories/25284 http://secunia.com/advisories/29041 http://securitytracker.com/id?1018057 http://www.vupen.com/english/advisories/2007/1815 http://www.vupen.com/english/advisories/2008/0612/references https://exchange.xforce.ibmcloud.com/vulnerabilities/34282

Share on: