BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
BID:15052
Info
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
| Bugtraq ID: | 15052 |
| Class: | Unknown |
| CVE: |
CVE-2005-4761 CVE-2005-4758 CVE-2005-4755 CVE-2005-4753 CVE-2005-4756 CVE-2005-4750 CVE-2005-4764 CVE-2005-4751 CVE-2005-4763 CVE-2005-4766 CVE-2005-4752 CVE-2005-4749 CVE-2005-4767 CVE-2005-4765 CVE-2005-4759 CVE-2005-4762 CVE-2005-4757 CVE-2005-4760 CVE-2005-4754 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 10 2005 12:00AM |
| Updated: | Sep 03 2007 10:21PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 5 BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 7 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems WebLogic Server for Win32 6.1 SP 8 BEA Systems WebLogic Server for Win32 6.1 SP 7 BEA Systems WebLogic Server for Win32 6.1 SP 6 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems WebLogic Server for Win32 6.1 SP 4 BEA Systems WebLogic Server for Win32 6.1 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 2 BEA Systems WebLogic Server for Win32 6.1 SP 1 BEA Systems WebLogic Server for Win32 6.1 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP6 BEA Systems Weblogic Server 6.1 SP 8 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems WebLogic Express for Win32 8.1 SP 5 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 7 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express for Win32 6.1 SP 8 BEA Systems WebLogic Express for Win32 6.1 SP 7 BEA Systems WebLogic Express for Win32 6.1 SP 6 BEA Systems WebLogic Express for Win32 6.1 SP 5 BEA Systems WebLogic Express for Win32 6.1 SP 4 BEA Systems WebLogic Express for Win32 6.1 SP 3 BEA Systems WebLogic Express for Win32 6.1 SP 2 BEA Systems WebLogic Express for Win32 6.1 SP 1 BEA Systems WebLogic Express for Win32 6.1 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 .0.1 SP 4 BEA Systems WebLogic Express 7.0 .0.1 SP 3 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP6 BEA Systems WebLogic Express 6.1 SP 8 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
BEA has released 24 advisories identifying various vulnerabilities affecting BEA WebLogic Server and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
We conjecture that some of these issues may allow an attacker to completely compromise a vulnerable computer.
These issues are currently being analyzed. This BID will be updated and individual BIDs will be released when further analysis is complete.
BEA has released 24 advisories identifying various vulnerabilities affecting BEA WebLogic Server and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
We conjecture that some of these issues may allow an attacker to completely compromise a vulnerable computer.
These issues are currently being analyzed. This BID will be updated and individual BIDs will be released when further analysis is complete.
Exploit / POC
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
Some of these issues do not require exlpoit code.
Currently we are not aware of any exploits for other issues requiring exploit code. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Some of these issues do not require exlpoit code.
Currently we are not aware of any exploits for other issues requiring exploit code. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
Solution:
BEA has released multiple advisories as well as fixes:
- An updated security advisory (BEA06-106.01) with updated fixes
- An updated security advisory (BEA06-87.02) with updated fixes. This advisory replaces BEA06-87.01 and BEA06-87.00.
Please see the referenced advisories for details.
An updated security advisory (BEA07-107.02) with updated fixes is available; this advisory replaces security advisory BEA05-107.01.
BEA Systems WebLogic Express for Win32 6.1 SP 7
BEA Systems WebLogic Express 6.1 SP 7
BEA Systems WebLogic Server for Win32 6.1 SP 7
BEA Systems Weblogic Server 7.0 SP 7
BEA Systems WebLogic Express 7.0 SP 7
BEA Systems WebLogic Server for Win32 7.0 SP 7
BEA Systems WebLogic Express for Win32 7.0 SP 7
Solution:
BEA has released multiple advisories as well as fixes:
- An updated security advisory (BEA06-106.01) with updated fixes
- An updated security advisory (BEA06-87.02) with updated fixes. This advisory replaces BEA06-87.01 and BEA06-87.00.
Please see the referenced advisories for details.
An updated security advisory (BEA07-107.02) with updated fixes is available; this advisory replaces security advisory BEA05-107.01.
BEA Systems WebLogic Express for Win32 6.1 SP 7
-
BEA Systems CR196369_610sp7_v4.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_610sp7_v4.jar
BEA Systems WebLogic Express 6.1 SP 7
-
BEA Systems CR196369_610sp7_v4.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_610sp7_v4.jar
BEA Systems WebLogic Server for Win32 6.1 SP 7
-
BEA Systems CR196369_610sp7_v4.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_610sp7_v4.jar
BEA Systems Weblogic Server 7.0 SP 7
-
BEA Systems CR196369_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_700sp7.jar
BEA Systems WebLogic Express 7.0 SP 7
-
BEA Systems CR196369_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_700sp7.jar
BEA Systems WebLogic Server for Win32 7.0 SP 7
-
BEA Systems CR196369_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_700sp7.jar
BEA Systems WebLogic Express for Win32 7.0 SP 7
-
BEA Systems CR196369_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR196369_700sp7.jar
References
BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
References:
References:
- BEA05-100.00 (BEA Systems)
- BEA05-101.00 (BEA Systems)
- BEA05-102.00 (BEA Systems)
- BEA05-103.00 (BEA Systems)
- BEA05-105.00 (BEA Systems)
- BEA05-106.00 (BEA Systems)
- BEA05-107.00 (BEA Systems)
- BEA05-80.02 (BEA Systems)
- BEA05-85.00 (BEA Systems)
- BEA05-86.00 (BEA Systems)
- BEA05-87.00 (BEA Systems)
- BEA05-88.00 (BEA Systems)
- BEA05-89.00 (BEA Systems)
- BEA05-90.00 (BEA Systems)
- BEA05-91.00 (BEA Systems)
- BEA05-92.00 (BEA Systems)
- BEA05-93.00 (BEA Systems)
- BEA05-94.00 (BEA Systems)
- BEA05-95.00 (BEA Systems)
- BEA05-96.00 (BEA Systems)
- BEA05-97.00 (BEA Systems)
- BEA05-98.00 (BEA Systems)
- BEA05-99.00 (BEA Systems)
- Security Advisory: (BEA06-106.01) (BEA Systems)
- Security Advisory: (BEA06-87.01) (BEA Systems)
- Weblogic (BEA Systems)
- Security Advisory: (BEA07-87.02) (BEA Systems)