CVE-2007-0416

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*

Information

Published : 2007-01-22 16:28

Updated : 2011-03-07 18:49


NVD link : CVE-2007-0416

Mitre link : CVE-2007-0416


JSON object : View

Advertisement

dedicated server usa

Products Affected

bea

  • weblogic_server