BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
BID:10544
Info
BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
| Bugtraq ID: | 10544 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2004 12:00AM |
| Updated: | Jun 14 2004 12:00AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
It is reported that WebLogic Server and WebLogic Express are affected by a remote denial of service vulnerability. Due to certain unspecified reasons, the server does not close connections properly, ultimately running out of sockets.
WebLogic Server and WebLogic Express 8.1 SP2 and prior are vulnerable to this issue.
It is reported that WebLogic Server and WebLogic Express are affected by a remote denial of service vulnerability. Due to certain unspecified reasons, the server does not close connections properly, ultimately running out of sockets.
WebLogic Server and WebLogic Express 8.1 SP2 and prior are vulnerable to this issue.
Exploit / POC
BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
Solution:
BEA has released an advisory BEA04-61.00 with fix information to address this issue. Please see the referenced advisory for more information.
BEA Systems WebLogic Express 8.1 SP 4
BEA Systems WebLogic Express for Win32 8.1 SP 4
BEA Systems WebLogic Server for Win32 8.1 SP 4
BEA Systems Weblogic Server 8.1 SP 4
Solution:
BEA has released an advisory BEA04-61.00 with fix information to address this issue. Please see the referenced advisory for more information.
BEA Systems WebLogic Express 8.1 SP 4
-
BEA Systems CR215121_81sp4.jar
ftp://ftpna.beasys.com/pub/releases/security/CR215121_81sp4.jar
BEA Systems WebLogic Express for Win32 8.1 SP 4
-
BEA Systems CR215121_81sp4.jar
ftp://ftpna.beasys.com/pub/releases/security/CR215121_81sp4.jar
BEA Systems WebLogic Server for Win32 8.1 SP 4
-
BEA Systems CR215121_81sp4.jar
ftp://ftpna.beasys.com/pub/releases/security/CR215121_81sp4.jar
BEA Systems Weblogic Server 8.1 SP 4
-
BEA Systems CR215121_81sp4.jar
ftp://ftpna.beasys.com/pub/releases/security/CR215121_81sp4.jar
References
BEA WebLogic Server And WebLogic Express Remote Denial of Service Vulnerability
References:
References:
- Security Advisory: (BEA04-61.00) (BEA Systems)
- Security Advisory: (BEA05-61.01) (BEA Systems)