BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
BID:13717
Info
BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
| Bugtraq ID: | 13717 |
| Class: | Design Error |
| CVE: |
CVE-2005-1742 CVE-2005-1743 CVE-2005-1744 CVE-2005-1745 CVE-2005-1746 CVE-2005-1747 CVE-2005-1748 CVE-2005-1749 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2005 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | The vendor disclosed most of these issues. Mitja Kolsek of ACROS Security disclosed the HTML injection and cross-site scripting issues. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems WebLogic Server for Win32 6.1 SP 7 BEA Systems WebLogic Server for Win32 6.1 SP 6 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems WebLogic Server for Win32 6.1 SP 4 BEA Systems WebLogic Server for Win32 6.1 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 2 BEA Systems WebLogic Server for Win32 6.1 SP 1 BEA Systems WebLogic Server for Win32 6.1 BEA Systems WebLogic Server for Win32 6.0 SP 2 BEA Systems WebLogic Server for Win32 6.0 SP 1 BEA Systems WebLogic Server for Win32 6.0 BEA Systems WebLogic Server for Win32 5.1 SP 4 BEA Systems WebLogic Server for Win32 5.1 SP 3 BEA Systems WebLogic Server for Win32 5.1 SP 2 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP6 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems Weblogic Server 6.0 SP 2 BEA Systems Weblogic Server 6.0 SP 1 BEA Systems Weblogic Server 6.0 BEA Systems WebLogic Portal 8.0 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express for Win32 6.1 SP 7 BEA Systems WebLogic Express for Win32 6.1 SP 6 BEA Systems WebLogic Express for Win32 6.1 SP 5 BEA Systems WebLogic Express for Win32 6.1 SP 4 BEA Systems WebLogic Express for Win32 6.1 SP 3 BEA Systems WebLogic Express for Win32 6.1 SP 2 BEA Systems WebLogic Express for Win32 6.1 SP 1 BEA Systems WebLogic Express for Win32 6.1 BEA Systems WebLogic Express for Win32 6.0 SP 2 BEA Systems WebLogic Express for Win32 6.0 SP 1 BEA Systems WebLogic Express for Win32 6.0 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 .0.1 SP 4 BEA Systems WebLogic Express 7.0 .0.1 SP 3 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP6 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 BEA Systems WebLogic Express 6.0 SP 2 BEA Systems WebLogic Express 6.0 SP 1 BEA Systems WebLogic Express 6.0 |
| Not Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 7 BEA Systems WebLogic Server for Win32 6.1 SP 8 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 6.1 SP 8 BEA Systems WebLogic Express for Win32 8.1 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 7 BEA Systems WebLogic Express for Win32 6.1 SP 8 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 6.1 SP 8 |
Discussion
BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
BEA WebLogic is susceptible to multiple vulnerabilities. The following specific issues have been identified:
- A denial-of-service vulnerability allows users with the 'Monitor security' role to reset JDBC connection pools, or to reduce the number of connections available.
- A denial-of-service vulnerability allows attackers to cause the failure of security exception auditing.
- An access-validation vulnerability in the security constraint system fails to force the currently logged-in users to reauthenticate to the application server once security constraints have been altered and the application has been redeployed, even if the new constraints preclude the users access.
- A local information-disclosure vulnerability as the 'UserLogin' control displays cleartext passwords of failed authentication attempts to standard output.
- A denial-of-service vulnerability in the cookie parsing code may cause clustered servers to slow down when cookies with an invalid host or port are processed.
- Multiple unspecified cross-site scripting vulnerabilities reside in the server console and login page. These issues allow attackers to execute script code in the context of the affected website, possibly allowing them to gain administrative access to the affected application server.
- A vulnerability in the embedded LDAP server allows remote attackers to anonymously bind to it. This allows for information disclosure, and possibly a denial-of-service condition due to resource exhaustion.
- An unspecified buffer overflow vulnerability may allow remote attackers to cause the instance to become unstable. This issue may allow remote attackers to cause a thread loop, consuming CPU resources. Due to the nature of buffer-overflow vulnerabilities, an attacker may be able to execute arbitrary machine code in the context of the affected application.
This BID will be split into individual BIDs in the future as further details become available.
BEA WebLogic is susceptible to multiple vulnerabilities. The following specific issues have been identified:
- A denial-of-service vulnerability allows users with the 'Monitor security' role to reset JDBC connection pools, or to reduce the number of connections available.
- A denial-of-service vulnerability allows attackers to cause the failure of security exception auditing.
- An access-validation vulnerability in the security constraint system fails to force the currently logged-in users to reauthenticate to the application server once security constraints have been altered and the application has been redeployed, even if the new constraints preclude the users access.
- A local information-disclosure vulnerability as the 'UserLogin' control displays cleartext passwords of failed authentication attempts to standard output.
- A denial-of-service vulnerability in the cookie parsing code may cause clustered servers to slow down when cookies with an invalid host or port are processed.
- Multiple unspecified cross-site scripting vulnerabilities reside in the server console and login page. These issues allow attackers to execute script code in the context of the affected website, possibly allowing them to gain administrative access to the affected application server.
- A vulnerability in the embedded LDAP server allows remote attackers to anonymously bind to it. This allows for information disclosure, and possibly a denial-of-service condition due to resource exhaustion.
- An unspecified buffer overflow vulnerability may allow remote attackers to cause the instance to become unstable. This issue may allow remote attackers to cause a thread loop, consuming CPU resources. Due to the nature of buffer-overflow vulnerabilities, an attacker may be able to execute arbitrary machine code in the context of the affected application.
This BID will be split into individual BIDs in the future as further details become available.
Exploit / POC
BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
Solution:
The vendor has released multiple advisories and fixes to address these issues. Please see the referenced advisories for details:
- BEA has released an updated advisory (BEA05-80.01) with additional fixes.
- BEA has released an updated advisory (BEA06-81.01) with additional fixes.
BEA Systems WebLogic Express for Win32 6.1 SP 7
BEA Systems WebLogic Express 6.1 SP 7
BEA Systems WebLogic Server for Win32 6.1 SP 7
BEA Systems WebLogic Express for Win32 7.0 SP 6
BEA Systems Weblogic Server 7.0 SP 6
BEA Systems WebLogic Express 7.0 SP 6
BEA Systems WebLogic Server for Win32 7.0 SP 6
BEA Systems Weblogic Server 8.1 SP 4
BEA Systems WebLogic Express for Win32 8.1 SP 4
BEA Systems WebLogic Server for Win32 8.1 SP 4
Solution:
The vendor has released multiple advisories and fixes to address these issues. Please see the referenced advisories for details:
- BEA has released an updated advisory (BEA05-80.01) with additional fixes.
- BEA has released an updated advisory (BEA06-81.01) with additional fixes.
BEA Systems WebLogic Express for Win32 6.1 SP 7
-
BEA Systems CR229334_610sp7.jar
ftp://ftpna.bea.com/pub/releases/security/CR229334_610sp7.jar
BEA Systems WebLogic Express 6.1 SP 7
-
BEA Systems CR229334_610sp7.jar
ftp://ftpna.bea.com/pub/releases/security/CR229334_610sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 7
-
BEA Systems CR229334_610sp7.jar
ftp://ftpna.bea.com/pub/releases/security/CR229334_610sp7.jar
BEA Systems WebLogic Express for Win32 7.0 SP 6
-
BEA Systems CR236810_700sp6.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_700sp6.jar
BEA Systems Weblogic Server 7.0 SP 6
-
BEA Systems CR236810_700sp6.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_700sp6.jar
BEA Systems WebLogic Express 7.0 SP 6
-
BEA Systems CR236810_700sp6.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_700sp6.jar
BEA Systems WebLogic Server for Win32 7.0 SP 6
-
BEA Systems CR236810_700sp6.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_700sp6.jar
BEA Systems Weblogic Server 8.1 SP 4
-
BEA Systems CR236810_810sp4.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_810sp4.jar
BEA Systems WebLogic Express for Win32 8.1 SP 4
-
BEA Systems CR236810_810sp4.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_810sp4.jar
BEA Systems WebLogic Server for Win32 8.1 SP 4
-
BEA Systems CR236810_810sp4.jar
ftp://ftpna.bea.com/pub/releases/security/CR236810_810sp4.jar
References
BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
References:
References:
- BEA WebLogic Server Security Alerts (BEA Systems)
- Security Advisory: (BEA05-75.00) (BEA Systems)
- Security Advisory: (BEA05-76.00) (BEA Systems)
- Security Advisory: (BEA05-77.00) (BEA Systems)
- Security Advisory: (BEA05-78.00) (BEA Systems)
- Security Advisory: (BEA05-79.00) (BEA Systems)
- Security Advisory: (BEA05-80.00) (BEA Systems)
- Security Advisory: (BEA05-80.01) (BEA Systems)
- Security Advisory: (BEA05-81.00) (BEA Systems)
- Security Advisory: (BEA05-82.00) (BEA Systems)
- Security Advisory: (BEA06-81.01) (BEA Systems)
- WebLogic Server Product Homepage (Oracle)
- ACROS Security: HTML Injection in BEA WebLogic Server Console (1) ("ACROS Security"
) - ACROS Security: HTML Injection in BEA WebLogic Server Console (2) ("ACROS Security"
) - BEA Systems Security Advisory: (BEA07-75.01) (BEA Systems)