Multiple BEA WebLogic Applications Multiple Vulnerabilities
BID:23979
Info
Multiple BEA WebLogic Applications Multiple Vulnerabilities
| Bugtraq ID: | 23979 |
| Class: | Unknown |
| CVE: |
CVE-2007-5576 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2007 12:00AM |
| Updated: | Feb 20 2008 04:15PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
BEA Systems WebLogic Workshop 8.1 SP 6 BEA Systems WebLogic Workshop 8.1 SP 5 BEA Systems WebLogic Workshop 8.1 SP 4 BEA Systems WebLogic Workshop 8.1 SP 3 BEA Systems WebLogic Workshop 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 10.0 BEA Systems WebLogic Portal 9.2 BEA Systems WebLogic Integration 8.1 SP6 BEA Systems WebLogic Integration 8.1 SP5 BEA Systems WebLogic Integration 8.1 SP4 BEA Systems WebLogic Integration 8.1 SP3 BEA Systems WebLogic Integration 8.1 SP2 BEA Systems WebLogic Integration 8.1 BEA Systems WebLogic Integration 9.2 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP6 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 BEA Systems WebLogic Express 9.2 BEA Systems WebLogic Express 9.1 BEA Systems WebLogic Express 9.0 BEA Systems WebLogic Express 10.0 BEA Systems WebLogic Enterprise 5.1 BEA Systems Tuxedo 8.1 BEA Systems Tuxedo 8.0 |
| Not Vulnerable: | |
Discussion
Multiple BEA WebLogic Applications Multiple Vulnerabilities
Multiple BEA WebLogic applications are affected by multiple vulnerabilities, including cross-site scripting, HTML-injection, information-disclosure, directory-traversal, security-bypass, brute-force, and denial-of-service issues.
An attacker can exploit these issues to gain privileged access to affected applications, to access potentially sensitive information that could aid in further attacks, or to deny service to legitimate users. Successful attacks can result in the compromise of the applications. Other attacks are also possible.
Multiple BEA WebLogic applications are affected by multiple vulnerabilities, including cross-site scripting, HTML-injection, information-disclosure, directory-traversal, security-bypass, brute-force, and denial-of-service issues.
An attacker can exploit these issues to gain privileged access to affected applications, to access potentially sensitive information that could aid in further attacks, or to deny service to legitimate users. Successful attacks can result in the compromise of the applications. Other attacks are also possible.
Exploit / POC
Multiple BEA WebLogic Applications Multiple Vulnerabilities
Some of these issues do not require specific exploit code.
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues do not require specific exploit code.
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple BEA WebLogic Applications Multiple Vulnerabilities
Solution:
The vendor has released patches to address these issues. Please see the references for more information.
BEA Systems WebLogic Express 9.0
BEA Systems Weblogic Server 7.0 SP 7
BEA Systems WebLogic Express 7.0
BEA Systems WebLogic Express 7.0 SP 7
Solution:
The vendor has released patches to address these issues. Please see the references for more information.
BEA Systems WebLogic Express 9.0
-
BEA Systems CR218580_900rp.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR218580_900rp.jar
BEA Systems Weblogic Server 7.0 SP 7
-
BEA Systems CR229334_610sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR229334_610sp7.jar -
BEA Systems CR274588_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR274588_700sp7.jar
BEA Systems WebLogic Express 7.0
-
BEA Systems CR229334_610sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR229334_610sp7.jar
BEA Systems WebLogic Express 7.0 SP 7
-
BEA Systems CR229334_610sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR229334_610sp7.jar -
BEA Systems CR274588_700sp7.jar
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/CR274588_700sp7.jar
References
Multiple BEA WebLogic Applications Multiple Vulnerabilities
References:
References:
- Vendor Homepage (BEA Systems)
- BEA Systems Security Advisory (BEA07-164.01) (BEA Systems)
- BEA07-158.00 (BEA Systems)
- BEA07-159.00 (BEA Systems)
- BEA07-160.00 (BEA Systems)
- BEA07-161.00 (BEA Systems)
- BEA07-162.00 (BEA Systems)
- BEA07-163.00 (BEA Systems)
- BEA07-164.00 (BEA Systems)
- BEA07-165.00 (BEA Systems)
- BEA07-166.00 (BEA Systems)
- BEA07-167.00 (BEA Systems)
- BEA07-168.00 (BEA Systems)
- BEA07-170.00 (BEA Systems)
- BEA07-80.03 (BEA Systems)
- BEA08-159.01 Security Advisories and Notifications (BEA)
- BEA08-80.04 Security Advisories and Notifications (BEA)