|
Oracle BEA WebLogic Server Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA33526
|
|
|
Release Date:
|
2009-01-14
|
|
Last Update:
|
2009-01-27
|
|
Popularity:
|
2,557 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Cross Site Scripting Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | BEA WebLogic Express 10.x BEA WebLogic Express 7.x BEA WebLogic Express 8.x BEA WebLogic Express 9.x BEA WebLogic Server 10.x BEA WebLogic Server 7.x BEA WebLogic Server 8.x BEA WebLogic Server 9.x
|
|
|
Binary Analysis:
|
BA649 :: Available for 1 Credit  BA659 :: Available for 1 Credit 
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Some vulnerabilities have been reported in Oracle BEA WebLogic Server, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
1) A boundary error exists in WebLogic plug-ins for Apache, Sun, and IIS Web servers when processing HTTP requests and can be exploited to cause a buffer overflow via a specially crafted HTTP request.
This vulnerability is reported in the following versions:
* Oracle WebLogic Server 10.3
* Oracle WebLogic Server 10.0 released through MP1
* Oracle WebLogic Server 9.2 released through MP3
* Oracle WebLogic Server 9.1
* Oracle WebLogic Server 9.0
* Oracle WebLogic Server 8.1 released through SP6
* Oracle WebLogic Server 7.0 released through SP7
2) An unspecified error can result in security policies not being enforced for web services. No further details are currently available.
This vulnerability is reported in Oracle WebLogic Server 10.3 GA on all platforms.
3) An unspecified error related to JSP and servlets can be exploited to disclose potentially sensitive information. No further details are currently available.
This vulnerability is reported in the following versions:
* Oracle WebLogic Server 10.3 GA on all platforms
* Oracle WebLogic Server 10.0 released through Maintenance Pack 1 on all platforms
* Oracle WebLogic Server 9.2 released through Maintenance Pack 3 on all platforms
* Oracle WebLogic Server 9.1 on all platforms
* Oracle WebLogic Server 9.0 on all platforms
4) Certain unspecified input in the WebLogic Console is not properly sanitised before being returned to a user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of an affected site.
This vulnerability is reported in the following versions:
* Oracle WebLogic Server 10.3
* Oracle WebLogic Server 10.0 released through Maintenance Pack 1 on all platforms
* Oracle WebLogic Server 9.2 released through Maintenance Pack 3 on all platforms
* Oracle WebLogic Server 9.1 on all platforms
* Oracle WebLogic Server 9.0 on all platforms
* Oracle WebLogic Server 8.1 released through Service Pack 6, on all platforms
* Oracle WebLogic Server 7.0 released through Service Pack 7, on all platforms
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|