CVE-2006-2470

WebLogic Server <9.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies.

References (4)

Core 4
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20130
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1828
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26464
Patch, Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/188

Scores

EPSS 0.0050
EPSS Percentile 66.4%

Details

Status published
Products (1)
bea/weblogic_server 9.0
Published May 19, 2006
Tracked Since Feb 18, 2026