BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks.
2008-02-21T01:44:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bea | weblogic_server | 9.0 | Yes |
Application | bea | weblogic_server | 9.0 | Yes |
Application | bea | weblogic_server | 9.1 | Yes |
Application | bea | weblogic_server | 9.1 | Yes |