BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
BID:26843
Info
BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
| Bugtraq ID: | 26843 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2007 12:00AM |
| Updated: | Dec 13 2007 05:22PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
BEA Systems WebLogic Mobility Server 3.6 SP1 BEA Systems WebLogic Mobility Server 3.6 BEA Systems WebLogic Mobility Server 3.5 BEA Systems WebLogic Mobility Server 3.3 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
BEA WebLogic Mobility Server is prone to a vulnerability that results in unauthorized file access.
Attackers can exploit this issue to gain access to potentially sensitive files that could aid in further attacks.
BEA WebLogic Mobility Server is prone to a vulnerability that results in unauthorized file access.
Attackers can exploit this issue to gain access to potentially sensitive files that could aid in further attacks.
Exploit / POC
BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
BEA Systems WebLogic Mobility Server 3.5
BEA Systems WebLogic Mobility Server 3.6
BEA Systems WebLogic Mobility Server 3.6 SP1
BEA Systems WebLogic Mobility Server 3.3
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
BEA Systems WebLogic Mobility Server 3.5
-
BEA Systems ImageConverterPatch.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/ImageConverterPatch.zip
BEA Systems WebLogic Mobility Server 3.6
-
BEA Systems ImageConverterPatch.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/ImageConverterPatch.zip
BEA Systems WebLogic Mobility Server 3.6 SP1
-
BEA Systems ImageConverterPatch.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/ImageConverterPatch.zip
BEA Systems WebLogic Mobility Server 3.3
-
BEA Systems ImageConverterPatch.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/ImageConverterPatch.zip
References
BEA WebLogic Mobility Server Image Converter Unspecified Unauthorized Access Vulnerability
References:
References:
- BEA WebLogic Server Homepage (BEA Systems)
- Security Advisory (BEA07-182.00) (BEA Systems)