Description
BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.
References (2)
Core 2
Core References
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/9034
Vendor Advisory vendor-advisory
x_refsource_bea
http://dev2dev.bea.com/pub/advisory/32
Scores
EPSS
0.0038
EPSS Percentile
59.8%
Details
Status
published
Products (3)
bea/weblogic_server
7.0 (13 CPE variants)
bea/weblogic_server
7.0.0.1 (9 CPE variants)
bea/weblogic_server
8.1 (4 CPE variants)
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026