VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2696

CVE-2004-2696

Description

BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.

Affected products

62
  • Bea/Weblogic Server62 versions
    cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*+ 61 more
    • cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp6:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp6:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:win32:*:*:*:*:*
    • (no CPE)range: 6.1, 7.0, 8.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.