« Volver al listado

CVE-2007-2697

Estado: ModificadaMedia (5.1)—

The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2697",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-05-16T01:19:00.000",
  "references": [
    {
      "url": "http://dev2dev.bea.com/pub/advisory/229",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/36072",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25284",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1018057",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1815",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34291",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://dev2dev.bea.com/pub/advisory/229",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/36072",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25284",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1018057",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1815",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34291",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service."
    },
    {
      "lang": "es",
      "value": "El servidor LDAP embebido en BEA WebLogic Express y WebLogic Server 7.0 hasta SP6, 8.1 hasta SP5, 9.0, y 9.1, en configuraciones concretas, no limita o monitoriza intentos fallidos de autenticación, lo cual permite a atacantes remotos llevar a cabo ataques de fuerza bruta contra la contraseña del administrador más fácilmente, o inundar el servidor con intentos de identificación y causar una denegación de servicio."
    }
  ],
  "lastModified": "2026-06-16T22:40:08.550",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9C5AFCF-79D8-4005-B800-B0C6BD461276"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBDF3AC0-0680-4EEE-898C-47D194667BE2"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6828CE4B-91E8-4688-977F-DC7BC21131C8"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBDB9094-78E8-4CBF-9F5F-321D5174F1EC"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E141AA86-C6D0-4FA8-9268-0FB0635DF9CF"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FB8930F-C6D8-40B9-8D08-751F5B47229B"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "893D9D88-43C4-4F9F-A364-0585DE6FA9E9"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D59F9859-7344-43F0-9348-E57FABB9E431"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D34E2925-DE2A-437F-B349-BD7103F4C37E"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A4EC87D-EF83-48C5-B516-A6A482D9F525"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16E3F943-D920-4C0A-8545-5CF7D792011F"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BBA04D4-BA2E-4495-85DE-38918A878012"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B46A3EBE-B268-427E-AAB5-62DDF255F1D1"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3024422-1CA9-4E5D-80D1-2F4B57FDAEBA"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp7:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "596178D8-B7BB-4793-81C1-119ED353CF2D"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E08D4CEA-9ACC-4869-BC87-3524A059914F"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADED8968-EA9C-4F0E-AD2F-BC834F4D8A58"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F5B2A06-CE19-4A57-9566-09FC1E259CDB"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7560131-A6AC-4BBB-AA2D-C7C63AB51226"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D18E22CC-A0FC-4BC7-AD39-2645F57486C1"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "893C2387-03E3-4F8E-9029-BC64C64239EF"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9429D939-FCC4-4BA7-90C4-BBEECE7309D0"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55661356-58E0-49D3-9C79-B4BB5EBE24CF"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0653ACAC-B0D9-4381-AB23-11D24852A414"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "107C2FC6-BC60-4817-8A21-14C81DA6DEF5"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A489A8E-D3AE-42DF-8DCF-5A9EF10778FA"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24E0BA12-971C-4DC4-8ED2-9B7DCD6390E7"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CA97F1A-49F7-4511-8959-D62155491DF5"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EDB38AA-CAC4-4C89-8484-7C2A75F8038F"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.0:ga:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98F632B9-0572-4563-BA41-262628A5CB7A"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCAAE8F1-CB25-4871-BE48-ABF7DFAD8AD6"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:express:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17280B97-D499-434E-BD89-FD348E9E2E0C"
            },
            {
              "criteria": "cpe:2.3:a:bea:weblogic_server:9.1:ga:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A585B339-442B-4408-9A44-E872FF4406A8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}