CVE-2004-0715
Last modified
CVE-2004-0715 is a vulnerability of currently unknown severity. The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bea | Weblogic Server | 7.0 |
| Bea | Weblogic Server | 8.1 |
References
- http://www.kb.cert.org/vuls/id/470470Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10130Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/470470Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10130Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0715?
How severe is CVE-2004-0715?
How do I fix CVE-2004-0715?
Are you affected by CVE-2004-0715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
