CVE-2007-2697 Information
Feb 14, 2021
cve
Description
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6 8.1 through SP5 9.0 and 9.1 when in certain configurations does not limit or audit failed authentication attempts which allows remote attackers to more easily conduct brute-force attacks against the administrator password or flood the server with login attempts and cause a denial of service.
Reference
http://dev2dev.bea.com/pub/advisory/229 http://osvdb.org/36072 http://secunia.com/advisories/25284 http://securitytracker.com/id?1018057 http://www.vupen.com/english/advisories/2007/1815 https://exchange.xforce.ibmcloud.com/vulnerabilities/34291
Share on: