BEA WebLogic contains a flaw that may lead to an unauthorized information disclosure. The problem is triggered when a client logs in by using one-way SSL without specifiying the user which results in unprotected network traffic.
Classification
Location:
Remote / Network Access
Attack Type:
Cryptographic
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 8.1 Service Pack 4 or higher, as it has been reported to fix this vulnerability. In addition, BEA Systems has released a patch for version 7.0 Service Pack 6 and 6.1 Service Pack 7.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.