Title : BEA WebLogic Security Provider Exceptions Handling Vulnerability VUPEN ID : VUPEN/ADV-2005-0603 CVE ID : CVE-2005-1743 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-24
Technical Description
A vulnerability was identified in BEA WebLogic Server and WebLogic Express, which may lead to incorrect identity on the thread or a failure to audit security exceptions. This issue occurs when a security provider has an internal error and throws an exception, which may lead to incorrect identity on the thread or a failure to audit security exceptions. No further details have been disclosed.