5.1

CVE-2007-2697

The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.

Data is provided by the National Vulnerability Database (NVD)
BeaWeblogic Server Version7.0
BeaWeblogic Server Version7.0 Editionexpress
BeaWeblogic Server Version7.0 Updatesp1
BeaWeblogic Server Version7.0 Updatesp1 Editionexpress
BeaWeblogic Server Version7.0 Updatesp2
BeaWeblogic Server Version7.0 Updatesp2 Editionexpress
BeaWeblogic Server Version7.0 Updatesp3
BeaWeblogic Server Version7.0 Updatesp3 Editionexpress
BeaWeblogic Server Version7.0 Updatesp4
BeaWeblogic Server Version7.0 Updatesp4 Editionexpress
BeaWeblogic Server Version7.0 Updatesp5
BeaWeblogic Server Version7.0 Updatesp5 Editionexpress
BeaWeblogic Server Version7.0 Updatesp6
BeaWeblogic Server Version7.0 Updatesp6 Editionexpress
BeaWeblogic Server Version7.0 Updatesp7 Editionexpress
BeaWeblogic Server Version8.1
BeaWeblogic Server Version8.1 Editionexpress
BeaWeblogic Server Version8.1 Updatesp1
BeaWeblogic Server Version8.1 Updatesp1 Editionexpress
BeaWeblogic Server Version8.1 Updatesp2
BeaWeblogic Server Version8.1 Updatesp2 Editionexpress
BeaWeblogic Server Version8.1 Updatesp3
BeaWeblogic Server Version8.1 Updatesp3 Editionexpress
BeaWeblogic Server Version8.1 Updatesp4
BeaWeblogic Server Version8.1 Updatesp4 Editionexpress
BeaWeblogic Server Version8.1 Updatesp5
BeaWeblogic Server Version8.1 Updatesp5 Editionexpress
BeaWeblogic Server Version9.0
BeaWeblogic Server Version9.0 Editionexpress
BeaWeblogic Server Version9.0 Updatega
BeaWeblogic Server Version9.1
BeaWeblogic Server Version9.1 Editionexpress
BeaWeblogic Server Version9.1 Updatega
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.17% 0.778
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P