Home    |    View Topics    |    Search    |    Contact Us    |   



Category:   Application (Web Server/CGI)  >   Oracle WebLogic Vendors:   BEA Systems, Oracle
Oracle BEA WebLogic Server and Portal Bugs Let Remote Authenticated Users Modify Data
SecurityTracker Alert ID:  1023062
SecurityTracker URL:
CVE Reference:   CVE-2009-2002, CVE-2009-3396, CVE-2009-3399   (Links to External Site)
Date:  Oct 20 2009
Impact:   Modification of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): Server 7.0.6, 8.1.5, 9.0, 9.1, 9.2.3, 10.0.1, 10.3; Portal 8.1.6, 9.2.3, 10.0.1, 10.2.1,
Description:   Three vulnerabilities were reported in WebLogic Server and Portal. A remote authenticated user can modify some data on the target application.

No details were provided.

The following researchers reported these and other Oracle vulnerabilities:

Yaniv Azaria of Imperva, Inc.; Cesar Cerrudo of Argeniss; Deniz Cevik of Intellect; Joxean Koret; Joxean Koret of iSIGHT Partners Global Vulnerability Partnership; Alexander Kornbrust of Red Database Security; David Litchfield of NGS Software; Ryan Permeh of McAfee Avert labs; Guy Pilosof of Sentrigo; Aviv Pode of Sentrigo; Alexandr Polyakov of Digital Security; Pawel Romanek of Asseco Business Solutions; Amichai Shulman of Imperva, Inc.; Rajat Swarup; Laszlo Toth; Luka Treiber of ACROS Security; Wei Wang of McAfee Avert labs; and Dennis Yurichev.

Impact:   A remote authenticated user can modify some data on the target application.
Solution:   The vendor has issued a fix, described in their Oct 2009 Critical Patch Update advisory.

The Oracle advisory is available at:

Vendor URL: (Links to External Site)
Cause:   Not specified
Underlying OS:  Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (NT), Windows (2000), Windows (2003)

Message History:   None.

 Source Message Contents

[Original Message Not Available for Viewing]

Go to the Top of This SecurityTracker Archive Page

Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2022, LLC