>> BEA WebLogic Active Directory LDAP Server Security Bypass
Title : BEA WebLogic Active Directory LDAP Server Security Bypass VUPEN ID : VUPEN/ADV-2005-0601 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-24
Technical Description
A vulnerability was identified in BEA WebLogic Server and WebLogic Express, which may be exploited by malicious users to bypass security restrictions. This issue occurs when Active Directory LDAP server is used as the authentication database and a user account is disabled but not deleted, which may allow the disabled user to continue to be able to log in to WebLogic Server.