BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
BID:10327
Info
BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
| Bugtraq ID: | 10327 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0471 |
| Remote: | No |
| Local: | Yes |
| Published: | May 11 2004 12:00AM |
| Updated: | May 12 2015 07:52PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
WebLogic Server and WebLogic Express are reported prone to a denial-of-service vulnerability that may allow an attacker to shut down a vulnerable server. The issue presents itself when a site restricts the ability to start or stop servers to users in the Admin and Operator security role.
WebLogic Server and WebLogic Express are reported prone to a denial-of-service vulnerability that may allow an attacker to shut down a vulnerable server. The issue presents itself when a site restricts the ability to start or stop servers to users in the Admin and Operator security role.
Exploit / POC
BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
Solution:
BEA has released advisories BEA04-60.00 and BEA07-60.01 to address this issue.
Please see the references for more information.
BEA Systems Weblogic Server 7.0 SP 4
BEA Systems WebLogic Server for Win32 7.0 SP 4
BEA Systems Weblogic Server 8.1 SP 1
BEA Systems WebLogic Server for Win32 8.1
BEA Systems Weblogic Server 8.1
BEA Systems WebLogic Express for Win32 8.1
BEA Systems WebLogic Express for Win32 8.1 SP 1
BEA Systems WebLogic Server for Win32 8.1 SP 1
BEA Systems WebLogic Express 8.1 SP 1
BEA Systems WebLogic Express 8.1
Solution:
BEA has released advisories BEA04-60.00 and BEA07-60.01 to address this issue.
Please see the references for more information.
BEA Systems Weblogic Server 7.0 SP 4
-
BEA Systems WebLogic Server 7.0 SP5
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems WebLogic Server for Win32 7.0 SP 4
-
BEA Systems WebLogic Server 7.0 SP5
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 8.1 SP 1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Server for Win32 8.1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems Weblogic Server 8.1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Express for Win32 8.1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Express for Win32 8.1 SP 1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Server for Win32 8.1 SP 1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Express 8.1 SP 1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
BEA Systems WebLogic Express 8.1
-
BEA Systems WebLogic Server 8.0 SP2
http://commerce.beasys.com/showallversions.jsp?family=WLS
References
BEA WebLogic Server and WebLogic Express Denial of Service Vulnerability
References:
References:
- Security Advisory: (BEA04-60.00) (BEA Systems)
- BEA Security Advisory BEA07-60.01 (BEA)