>> BEA WebLogic Server JDBC Connection Reset Vulnerability
Title : BEA WebLogic Server JDBC Connection Reset Vulnerability VUPEN ID : VUPEN/ADV-2005-0602 CVE ID : CVE-2005-1742 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-24
Technical Description
A vulnerability was identified in BEA WebLogic Server and WebLogic Express, which may be exploited by malicious users to shrink or reset JDBC connection pools. This issue is due to an unspecified error when using the Monitor security role, which may be exploited by a user granted the Monitor security role to shrink or reset JDBC connection pools. No further details have been disclosed.