VYPR
Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Jun 16, 2026

CVE-2005-4767

CVE-2005-4767

Description

BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out a username after the maximum number of invalid login attempts, which makes it easier for remote attackers to guess the password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

41
  • Bea/WebLogic Server39 versions
    cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*+ 38 more
    • cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp3:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp4:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp5:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:sp6:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:7.0:*:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp1:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp2:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp3:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp4:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:sp5:win32:*:*:*:*:*
    • cpe:2.3:a:bea:weblogic_server:8.1:*:win32:*:*:*:*:*
  • Range: <=8.1 SP5, <=7.0 SP6
  • Range: <=8.1 SP5, <=7.0 SP6

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.