CVE-2005-4766
5.4
Vector
AV:N/AC:H/Au:N/C:C/I:N/A:N
Exploitability: 4.9 / Impact: 6.9
Source: NVD
Description
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.
Affected (33)
Products: Bea: Weblogic Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
References (6)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.