Vulnerabilities > CVE-2005-4765 - Multiple vulnerability in BEA Weblogic Server 7.0/8.1

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
bea

Summary

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection. Condition: when using the weblogic.Deployer command with the t3 protocol.

Vulnerable Configurations

Part Description Count
Application
Bea
36