Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgc7-vcfh-c73q

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.

BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.

EPSS

Процентиль: 82%
0.01811
Низкий

Связанные уязвимости

nvd
почти 22 года назад

BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.

EPSS

Процентиль: 82%
0.01811
Низкий