|
BEA WebLogic Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA10218
|
|
|
Release Date:
|
2003-11-13
|
|
Popularity:
|
10,647 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of sensitive information DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | BEA WebLogic Express 6.x BEA WebLogic Express 7.x BEA WebLogic Express 8.x BEA WebLogic Server 6.x BEA WebLogic Server 7.x BEA WebLogic Server 8.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: BEA has issued patches for BEA WebLogic Server and Express. These fix 5 different vulnerabilities, which can be exploited to cause a Denial of Service or expose sensitive information.
1) The proxy plug-in fails to handle certain incorrectly formatted URLs allowing malicious people to crash the proxy plug-in. This causes the websites to become inaccessible.
2) WebLogic may fail to wrap T3 in SSL when the URI handler has been specified as T3S. This happens if the port for the non-SSL enabled port is specified. This may expose data, which should be protected.
3) Passwords for foreign JMS providers are showed in clear-text in the console and is stored in clear-text in the "config.xml" file. This may expose the passwords to untrusted users.
4) Node Manager fails to handle invalid data such as data generated by port scanning tools. This may cause Node Manager to crash or stop responding.
5) The default settings for sites expose MBeanHome to anonymous users from JNDI with RMI access. This may expose various configuration MBeans.
WebLogic Server and Express 6.1 is affected by issues 1, 4, and 5.
WebLogic Server and Express 7.0 is affected by issues 1, 2, 4, and 5.
WebLogic Server and Express 8.1 is affected by issues 1, 2, 3, 4, and 5.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|