CVE-2005-1742

BEA WebLogic Server & WebLogic Express <8.1 SP3 - Info Disclosure

Title source: llm
STIX 2.1

Description

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15486
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0602
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014049
Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/125
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13717

Scores

EPSS 0.0041
EPSS Percentile 61.6%

Details

Status published
Products (4)
bea/weblogic_server 6.0 (9 CPE variants)
bea/weblogic_server 6.1 (20 CPE variants)
bea/weblogic_server 7.0 (18 CPE variants)
bea/weblogic_server 7.0.0.1 (3 CPE variants)
Published May 24, 2005
Tracked Since Feb 18, 2026