>> BEA WebLogic Embedded LDAP Server Denial of Service Vulnerability
Title : BEA WebLogic Embedded LDAP Server Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2005-0608 CVE ID : CVE-2005-1748 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-24
Technical Description
A vulnerability was identified in BEA WebLogic Server and WebLogic Express, which may be exploited by attackers to disclose sensitive information or cause a denial of service. This flaw is due to unspecified errors that could be exploited by remote attackers to bind anonymously to the embedded LDAP server and look at user entries (but not attributes), or cause a denial of service against the embedded LDAP server by creating many connections to the LDAP server. No further details have been disclosed.