The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," which allows remote attackers to access administrative data or functionality.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-05-16T01:00:00

Updated: 2024-08-07T13:49:57.548Z

Reserved: 2007-05-15T00:00:00

Link: CVE-2007-2695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-16T01:19:00.000

Modified: 2024-11-21T00:31:25.863

Link: CVE-2007-2695

cve-icon Redhat

No data.