CVE-2004-2696
Last modified
CVE-2004-2696 is a vulnerability of currently unknown severity. BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.. EPSS estimates a 1.29% chance of exploitation in the next 30 days.
Description
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bea | Weblogic Server | 6.1 |
| Bea | Weblogic Server | 7.0 |
| Bea | Weblogic Server | 7.0.0.1 |
| Bea | Weblogic Server | 8.1 |
References
- http://secunia.com/advisories/11865Vendor Advisory
- http://secunia.com/advisories/11865Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2696?
How severe is CVE-2004-2696?
How do I fix CVE-2004-2696?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2690Unrestricted file upload vulnerability in the Administration…
- CVE-2004-2691Unspecified vulnerability in 3Com SuperStack 3 4400 switches…
- CVE-2004-2692The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 wi…
- CVE-2004-2693HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Librarie…
- CVE-2004-2694Microsoft Outlook Express 6.0 allows remote attackers to byp…
- CVE-2004-2695SQL injection vulnerability in the Authorize.net callback co…
- CVE-2004-2697The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for…
- CVE-2004-2698Race condition in IMWheel 1.0.0pre11 and earlier, when runni…
- CVE-2004-2699deleteicon.aspx in AspDotNetStorefront 3.3 allows remote att…
- CVE-2004-2700Unrestricted file upload vulnerability in AspDotNetStorefron…
- CVE-2004-2701Cross-site scripting (XSS) vulnerability in signin.aspx for …
- CVE-2004-2702Cross-site scripting (XSS) vulnerability in login_up.php3 in…
Are you affected by CVE-2004-2696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
