>> BEA WebLogic Authentication Failure Information Disclosure Issue
Title : BEA WebLogic Authentication Failure Information Disclosure Issue VUPEN ID : VUPEN/ADV-2005-0160 CVE ID : CVE-2005-0432 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-02-15
Technical Description
A new vulnerability was identified in BEA WebLogic, which could be exploited by attackers to conduct brute force attacks. Under certain circumstances, an attacker may be able to determine the cause of a failed authentication attempt, which could be used by attackers to mount brute force attacks to guess a password.