HomeBeaCVE-2007-2697

CVE-2007-2697

UNKNOWN
5.1CVSS
Published: 2007-05-16
Updated: 2025-04-09
AI Analysis

Description

The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.

CVSS Metrics

Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Access Vector
network
Access Cmplx
high
Auth
none
Confidentiality
partial
Integrity
partial
Availability
partial
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
BEA
Published
5/16/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

bea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_serverbea : weblogic_server

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-2697 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com