CVE-2006-2461

BEA WebLogic Server <8.1 SP4 - Info Disclosure

Title source: llm
STIX 2.1

Description

BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic.

References (5)

Core 5
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20130
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016102
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1828
Patch, Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/194
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26459

Scores

EPSS 0.0048
EPSS Percentile 65.2%

Details

Status published
Products (1)
bea/weblogic_server 8.1 (4 CPE variants)
Published May 19, 2006
Tracked Since Feb 18, 2026