CVE-2007-2697
Estado: ModificadaMedia (5.1)—
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
- Puntuación base: 5.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.27%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://dev2dev.bea.com/pub/advisory/229
- http://osvdb.org/36072
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34291
- http://dev2dev.bea.com/pub/advisory/229
- http://osvdb.org/36072
- http://secunia.com/advisories/25284
- http://securitytracker.com/id?1018057
- http://www.vupen.com/english/advisories/2007/1815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34291
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-2697",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-05-16T01:19:00.000",
"references": [
{
"url": "http://dev2dev.bea.com/pub/advisory/229",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/36072",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25284",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018057",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1815",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34291",
"source": "cve@mitre.org"
},
{
"url": "http://dev2dev.bea.com/pub/advisory/229",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/36072",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25284",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018057",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1815",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34291",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service."
},
{
"lang": "es",
"value": "El servidor LDAP embebido en BEA WebLogic Express y WebLogic Server 7.0 hasta SP6, 8.1 hasta SP5, 9.0, y 9.1, en configuraciones concretas, no limita o monitoriza intentos fallidos de autenticación, lo cual permite a atacantes remotos llevar a cabo ataques de fuerza bruta contra la contraseña del administrador más fácilmente, o inundar el servidor con intentos de identificación y causar una denegación de servicio."
}
],
"lastModified": "2026-06-16T22:40:08.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9C5AFCF-79D8-4005-B800-B0C6BD461276"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBDF3AC0-0680-4EEE-898C-47D194667BE2"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6828CE4B-91E8-4688-977F-DC7BC21131C8"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBDB9094-78E8-4CBF-9F5F-321D5174F1EC"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E141AA86-C6D0-4FA8-9268-0FB0635DF9CF"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FB8930F-C6D8-40B9-8D08-751F5B47229B"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "893D9D88-43C4-4F9F-A364-0585DE6FA9E9"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D59F9859-7344-43F0-9348-E57FABB9E431"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D34E2925-DE2A-437F-B349-BD7103F4C37E"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A4EC87D-EF83-48C5-B516-A6A482D9F525"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16E3F943-D920-4C0A-8545-5CF7D792011F"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BBA04D4-BA2E-4495-85DE-38918A878012"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B46A3EBE-B268-427E-AAB5-62DDF255F1D1"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3024422-1CA9-4E5D-80D1-2F4B57FDAEBA"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:7.0:sp7:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "596178D8-B7BB-4793-81C1-119ED353CF2D"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E08D4CEA-9ACC-4869-BC87-3524A059914F"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADED8968-EA9C-4F0E-AD2F-BC834F4D8A58"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F5B2A06-CE19-4A57-9566-09FC1E259CDB"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7560131-A6AC-4BBB-AA2D-C7C63AB51226"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D18E22CC-A0FC-4BC7-AD39-2645F57486C1"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "893C2387-03E3-4F8E-9029-BC64C64239EF"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9429D939-FCC4-4BA7-90C4-BBEECE7309D0"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55661356-58E0-49D3-9C79-B4BB5EBE24CF"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0653ACAC-B0D9-4381-AB23-11D24852A414"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "107C2FC6-BC60-4817-8A21-14C81DA6DEF5"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A489A8E-D3AE-42DF-8DCF-5A9EF10778FA"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24E0BA12-971C-4DC4-8ED2-9B7DCD6390E7"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CA97F1A-49F7-4511-8959-D62155491DF5"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EDB38AA-CAC4-4C89-8484-7C2A75F8038F"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.0:ga:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98F632B9-0572-4563-BA41-262628A5CB7A"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCAAE8F1-CB25-4871-BE48-ABF7DFAD8AD6"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:*:express:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17280B97-D499-434E-BD89-FD348E9E2E0C"
},
{
"criteria": "cpe:2.3:a:bea:weblogic_server:9.1:ga:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A585B339-442B-4408-9A44-E872FF4406A8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}