Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BEA WebLogic Server SSL客户应用程序会话劫持漏洞
Vulnerability Description
BEA WebLogic Server 7.0 SP7版本, 8.1 SP2 至 SP6, 9.0, 9.1, 9.2 Gold 至 MP2, 以及10.0版本的SSL客户应用程序有时候在其他cipher不能使用时,选择无效cipher,这可能会允许远程攻击者劫持会话。
CVSS Information
N/A
Vulnerability Type
N/A