Oracle WebLogic Server Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions
|
|
SecurityTracker Alert ID: 1020498
|
|
SecurityTracker URL: http://securitytracker.com/id?1020498
|
|
CVE Reference: CVE-2008-2576
, CVE-2008-2577
, CVE-2008-2578
, CVE-2008-2579
, CVE-2008-2580
, CVE-2008-2581
, CVE-2008-2582
(Links to External Site)
|
Date: Jul 16 2008
|
Impact: Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Oracle Security Advisory
|
Version(s): 10.0 MP1 and prior versions
|
Description: Several vulnerabilities were reported in Oracle WebLogic Server. A remote user can execute arbitrary code on the target system. A remote user can cause denial of service conditions.
A remote user can exploit several unspecified vulnerabilities to affect the confidentiality and integrity of data on the target system.
A
remote user can cause unspecified "partial" denial of service conditions.
No details were provided.
The following versions
are affected:
- Oracle WebLogic Server (formerly BEA WebLogic Server) 10.0 released through MP1
- Oracle WebLogic Server (formerly
BEA WebLogic Server) 9.0, 9.1, 9.2 released through MP3
- Oracle WebLogic Server (formerly BEA WebLogic Server) 8.1 released through
SP6
- Oracle WebLogic Server (formerly BEA WebLogic Server) 7.0 released through SP7
- Oracle WebLogic Server (formerly BEA WebLogic
Server) 6.1 released through SP7
The following researchers reported these and other Oracle vulnerabilities:
Flavio Casetta
of Yocoya; Esteban Martinez Fayo of Application Security, Inc.; Johannes Greil of SEC Consult; guyp of Sentrigo; Joxean Koret; Alexander
Kornbrust of Red Database Security; Stephen Kost of Integrigy; Dave Lewis; David Litchfield of NGS Software; Hirofumi Oka of JPCERT/CC
Vulnerability Handling Team; Tanel Poder; Alexandr Polyakov of Digital Security; Andrea Purificato; and Dave Wichers of Aspect Security.
|
Impact: A remote user can access and modify data on the target system.
A remote user can cause denial of service conditions.
|
Solution: The vendor has issued a fix, described in their July 2008 Critical Patch Update advisory.
The Oracle advisory is available at:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html
|
Vendor URL: www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (NT), Windows (2000), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|