BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
BID:10328
Info
BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
| Bugtraq ID: | 10328 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 11 2004 12:00AM |
| Updated: | May 11 2004 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
BEA WebLogic Builder and the SecurityRoleAssignmentMBean.toXML() method are reported prone to an issue that could result in security properties of a Servlet container being compromised. This will result in the Servlet container assigning default settings for the security role, resulting in the web application being available to unauthorized users.
BEA WebLogic Builder and the SecurityRoleAssignmentMBean.toXML() method are reported prone to an issue that could result in security properties of a Servlet container being compromised. This will result in the Servlet container assigning default settings for the security role, resulting in the web application being available to unauthorized users.
Exploit / POC
BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
Solution:
BEA has released an advisory (BEA04-59.00) and fixes to address this issue. Please see referenced for further details regarding obtaining and applying an appropriate fix, fixes are linked below.
BEA Systems WebLogic Express 7.0 SP 5
BEA Systems Weblogic Server 7.0 SP 5
BEA Systems WebLogic Server for Win32 7.0 SP 5
BEA Systems WebLogic Express for Win32 7.0 SP 5
BEA Systems Weblogic Server 8.1 SP 2
BEA Systems WebLogic Server for Win32 8.1 SP 2
BEA Systems WebLogic Express 8.1 SP 2
BEA Systems WebLogic Express for Win32 8.1 SP 2
Solution:
BEA has released an advisory (BEA04-59.00) and fixes to address this issue. Please see referenced for further details regarding obtaining and applying an appropriate fix, fixes are linked below.
BEA Systems WebLogic Express 7.0 SP 5
-
BEA Systems CR171885_70sp5.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_70sp5.jar
BEA Systems Weblogic Server 7.0 SP 5
-
BEA Systems CR171885_70sp5.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_70sp5.jar
BEA Systems WebLogic Server for Win32 7.0 SP 5
-
BEA Systems CR171885_70sp5.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_70sp5.jar
BEA Systems WebLogic Express for Win32 7.0 SP 5
-
BEA Systems CR171885_70sp5.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_70sp5.jar
BEA Systems Weblogic Server 8.1 SP 2
-
BEA Systems CR171885_810sp2.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_810sp2.jar
BEA Systems WebLogic Server for Win32 8.1 SP 2
-
BEA Systems CR171885_810sp2.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_810sp2.jar
BEA Systems WebLogic Express 8.1 SP 2
-
BEA Systems CR171885_810sp2.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_810sp2.jar
BEA Systems WebLogic Express for Win32 8.1 SP 2
-
BEA Systems CR171885_810sp2.jar
ftp://ftpna.beasys.com/pub/releases/security/CR171885_810sp2.jar
References
BEA WebLogic Server And WebLogic Express Lowered Security Settings Vulnerability
References:
References: