VYPR
Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Jun 16, 2026

CVE-2005-4705

CVE-2005-4705

Description

BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection.

Affected products

35
  • Bea/WebLogic Server34 versions
    cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*+ 33 more
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:6.1:sp7:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*
    • (no CPE)range: <=8.1 SP4, <=7.0 SP6, <=6.1 SP7
  • Range: <=8.1 SP4, <=7.0 SP6, <=6.1 SP7

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.