BEA WebLogic Server Remote Filesystem Access Vulnerability
BID:17166
Info
BEA WebLogic Server Remote Filesystem Access Vulnerability
| Bugtraq ID: | 17166 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2006 12:00AM |
| Updated: | May 16 2006 11:04PM |
| Credit: | Discovered by S21sec. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 6.1 SP 7 BEA Systems WebLogic Server for Win32 6.1 SP 6 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems WebLogic Server for Win32 6.1 SP 4 BEA Systems WebLogic Server for Win32 6.1 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 2 BEA Systems WebLogic Server for Win32 6.1 SP 1 BEA Systems WebLogic Server for Win32 6.1 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Server Remote Filesystem Access Vulnerability
BEA WebLogic Server is prone to a vulnerability that could allow remote access to the local filesystem.
WebLogic Server 6.1 is vulnerable.
BEA WebLogic Server is prone to a vulnerability that could allow remote access to the local filesystem.
WebLogic Server 6.1 is vulnerable.
Exploit / POC
BEA WebLogic Server Remote Filesystem Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
BEA WebLogic Server Remote Filesystem Access Vulnerability
Solution:
This issue has been addressed in WebLogic Server 6.1 Service Pack 7.
BEA has released an updated advisory (BEA06-120.01) to replace advisory BEA06-120.00. The vendor has reported that this issue affects only Windows platforms; it does not affect other platforms as previously reported.
BEA Systems WebLogic Server for Win32 6.1 SP 2
BEA Systems WebLogic Server for Win32 6.1 SP 5
BEA Systems WebLogic Server for Win32 6.1 SP 4
BEA Systems WebLogic Server for Win32 6.1 SP 6
BEA Systems WebLogic Server for Win32 6.1 SP 1
BEA Systems WebLogic Server for Win32 6.1 SP 3
BEA Systems WebLogic Server for Win32 6.1 SP 7
BEA Systems WebLogic Server for Win32 6.1
Solution:
This issue has been addressed in WebLogic Server 6.1 Service Pack 7.
BEA has released an updated advisory (BEA06-120.01) to replace advisory BEA06-120.00. The vendor has reported that this issue affects only Windows platforms; it does not affect other platforms as previously reported.
BEA Systems WebLogic Server for Win32 6.1 SP 2
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 5
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 4
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 6
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 1
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 3
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1 SP 7
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
BEA Systems WebLogic Server for Win32 6.1
-
BEA Systems CR198547_61sp7.jar
ftp://ftpna.beasys.com/pub/releases/security/CR198547_61sp7.jar
References
BEA WebLogic Server Remote Filesystem Access Vulnerability
References:
References:
- BEA06-120.01 (BEA Systems)
- Security Advisory: (BEA06-120.00) (BEA Systems)
- WebLogic Server Product Homepage (Oracle)