5
CVSSv2

CVE-2003-1221

Published: 31/12/2003 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

BEA WebLogic Express and Server 7.0 up to and including 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow malicious users to sniff sessions.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 7.0.0.1

bea weblogic server 7.0

bea weblogic server 8.1