BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
BID:16215
Info
BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
| Bugtraq ID: | 16215 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2006 12:00AM |
| Updated: | Jan 12 2006 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 5 BEA Systems WebLogic Server for Win32 8.1 SP 4 BEA Systems WebLogic Server for Win32 8.1 SP 3 BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 7 BEA Systems WebLogic Server for Win32 7.0 SP 6 BEA Systems WebLogic Server for Win32 7.0 SP 5 BEA Systems WebLogic Server for Win32 7.0 SP 4 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems WebLogic Server for Win32 6.1 SP 8 BEA Systems WebLogic Server for Win32 6.1 SP 7 BEA Systems WebLogic Server for Win32 6.1 SP 6 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems WebLogic Server for Win32 6.1 SP 4 BEA Systems WebLogic Server for Win32 6.1 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 2 BEA Systems WebLogic Server for Win32 6.1 SP 1 BEA Systems WebLogic Server for Win32 6.1 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP6 BEA Systems Weblogic Server 6.1 SP 8 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems WebLogic Express for Win32 8.1 SP 5 BEA Systems WebLogic Express for Win32 8.1 SP 4 BEA Systems WebLogic Express for Win32 8.1 SP 3 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 7 BEA Systems WebLogic Express for Win32 7.0 SP 6 BEA Systems WebLogic Express for Win32 7.0 SP 5 BEA Systems WebLogic Express for Win32 7.0 SP 4 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express for Win32 6.1 SP 8 BEA Systems WebLogic Express for Win32 6.1 SP 7 BEA Systems WebLogic Express for Win32 6.1 SP 6 BEA Systems WebLogic Express for Win32 6.1 SP 5 BEA Systems WebLogic Express for Win32 6.1 SP 4 BEA Systems WebLogic Express for Win32 6.1 SP 3 BEA Systems WebLogic Express for Win32 6.1 SP 2 BEA Systems WebLogic Express for Win32 6.1 SP 1 BEA Systems WebLogic Express for Win32 6.1 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 .0.1 SP 4 BEA Systems WebLogic Express 7.0 .0.1 SP 3 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP6 BEA Systems WebLogic Express 6.1 SP 8 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
BEA WebLogic Server and WebLogic Express are susceptible to a remote information disclosure vulnerability. This issue is due to the affected server application improperly disclosing potentially sensitive configuration information to anonymous users.
This issue allows remote attackers to gain access to potentially sensitive information that may aid them in further attacks.
BEA WebLogic Server and WebLogic Express are susceptible to a remote information disclosure vulnerability. This issue is due to the affected server application improperly disclosing potentially sensitive configuration information to anonymous users.
This issue allows remote attackers to gain access to potentially sensitive information that may aid them in further attacks.
Exploit / POC
BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for further information on resolving this issue.
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for further information on resolving this issue.
References
BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
References:
References:
- BEA WebLogic Server Security Alerts (BEA Systems)
- Security Advisory: (BEA03-43.00) (BEA Systems)
- WebLogic Server Product Homepage (Oracle)