BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.
| Software | From | Fixed in |
|---|---|---|
| bea / weblogic_server | 8.1 | 8.1.x |
| bea / weblogic_server | - | 8.1.x |