Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
|
WebLogic Bugs Let Remote Users Execute Arbitary Code, Acces and Modify Information, and Deny Service
|
|
SecurityTracker Alert ID: 1021056
|
|
SecurityTracker URL: http://securitytracker.com/id?1021056
|
|
CVE Reference: CVE-2008-4008
, CVE-2008-4009
, CVE-2008-4010
, CVE-2008-4011
, CVE-2008-4012
, CVE-2008-4013
(Links to External Site)
|
Date: Oct 15 2008
|
Impact: Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Oracle Security Advisory
|
Version(s): 6.1 SP7, 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP1, 10.3
|
Description: Several vulnerabilities were reported in WebLogic. A remote user can execute arbitrary code on the target system. A remote user can access and modify data on the target system. A remote user can cause denial of service conditions.
A remote user can send specially crafted data to trigger a flaw in the WebLogic Server Plugins for Apache and execute arbitrary code
on the target system [CVE-2008-4008].
Other vulnerabilities also exist in the WebLogic Server [CVE-2008-4009, CVE-2008-4011,
CVE-2008-4013] and WebLogic Workshop [CVE-2008-4010, CVE-2008-4012] products are affected.
A remote user can exploit several
unspecified vulnerabilities to affect the confidentiality and integrity of data on the target system.
A remote user can cause
unspecified denial of service conditions.
No details were provided.
The following researchers reported these and other Oracle
vulnerabilities:
Esteban Martinez Fayo of Application Security, Inc.; Pete Finnigan; Tony Fogarty of DNV; guyp of Sentrigo; Jack
Kanter of Integrigy; Joxean Koret; Alexander Kornbrust of Red Database Security; Slavik Markovich of Sentrigo; Amichai Shulman of
Imperva, Inc.; and Chris Valasek of IBM Corp.
|
Impact: A remote user can execute arbitrary code on the target system.
A remote user can access and modify data on the target system.
A remote user can cause denial of service conditions.
|
Solution: The vendor has issued a fix, described in their October 2008 Critical Patch Update advisory.
The Oracle advisory is available at:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html
|
Vendor URL: www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (NT), Windows (2000), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 14 Oct 2008 08:02:57 -0400
Subject: Oracle WebLogic Server
|
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2008.html
|
|
Go to the Top of This SecurityTracker Archive Page
|