BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
BID:27893
Info
BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
| Bugtraq ID: | 27893 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 19 2008 12:00AM |
| Updated: | Jun 02 2008 11:23PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Workshop 8.1 SP 6 BEA Systems WebLogic Workshop 8.1 SP 5 BEA Systems WebLogic Workshop 8.1 SP 4 BEA Systems WebLogic Workshop 8.1 SP 3 BEA Systems WebLogic Workshop 8.1 SP 2 BEA Systems WebLogic Workshop 9.3 BEA Systems WebLogic Workshop 9.2 BEA Systems WebLogic Workshop 9.1 BEA Systems WebLogic Workshop 9.0 BEA Systems WebLogic Workshop 10.0 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 10.0 BEA Systems WebLogic Portal 8.1 SP6 BEA Systems WebLogic Portal 8.1 SP5 BEA Systems WebLogic Portal 8.1 SP4 BEA Systems WebLogic Portal 8.1 SP3 BEA Systems WebLogic Portal 8.1 SP2 BEA Systems WebLogic Portal 8.1 SP1 BEA Systems WebLogic Portal 8.1 BEA Systems WebLogic Portal 9.2 BEA Systems WebLogic Portal 7.0 BEA Systems WebLogic Portal 10.0 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP 8 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 BEA Systems WebLogic Express 9.2 BEA Systems WebLogic Express 9.1 BEA Systems WebLogic Express 9.0 BEA Systems WebLogic Express 8.1.0 SP 6 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 10.0 BEA Systems Plumtree Foundation 6.0 BEA Systems Plumtree Collaboration 4.1 BEA Systems AquaLogic Interaction 6.1 MP1 BEA Systems AquaLogic Collaboration 4.2 |
| Not Vulnerable: | |
Discussion
BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
BEA has released 17 advisories identifying various vulnerabilities affecting WebLogic Server, WebLogic Portal, WebLogic Workshop, AquaLogic Interaction, BEA Plumtree Foundation, AquaLogic Collaboration, and BEA Plumtree Collaboration. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
BEA has released 17 advisories identifying various vulnerabilities affecting WebLogic Server, WebLogic Portal, WebLogic Workshop, AquaLogic Interaction, BEA Plumtree Foundation, AquaLogic Collaboration, and BEA Plumtree Collaboration. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
Exploit / POC
BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
Specific exploits are not required for some of these issues.
An attacker can exploit some of these issues through a browser. For some issues, the attacker must have local interactive access to the affected computer. For the cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
Specific exploits are not required for some of these issues.
An attacker can exploit some of these issues through a browser. For some issues, the attacker must have local interactive access to the affected computer. For the cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the referenced advisories for details on obtaining the appropriate updates. Some of these updates may be installed with the smart update tool.
Solution:
The vendor has released updates to address these issues. Please see the referenced advisories for details on obtaining the appropriate updates. Some of these updates may be installed with the smart update tool.
References
BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities
References:
References:
- Weblogic (BEA Systems)
- WebLogic Portal Product Page (BEA Systems)
- WebLogic Server Product Homepage (Oracle)
- ACROS Security: HTML Injection in BEA WebLogic Server Console (ASPR #2008-03-11- ('ACROS Security'
) - ACROS Security: Session Fixation Vulnerability in WebLogic Administration Consol ('ACROS Security'
) - BEA Security Advisory (BEA08-183.00) Security policies on a WebLogic Portal Page (BEA Systems)
- BEA Security Advisory (BEA08-184.00) An entitlement on an instance of a floatabl (BEA Systems)
- BEA Security Advisory (BEA08-185.00) Cross-site scripting (XSS (BEA Systems)
- BEA Security Advisory (BEA08-186.00) BEA Plumtree Portal cross site scripting (X (BEA Systems)
- BEA Security Advisory (BEA08-187.00) Web Service WSDL and policy is exposed to u (BEA)
- BEA Security Advisory (BEA08-188.00) JavaScript can be injected into the WLP Gro (BEA)
- BEA Security Advisory (BEA08-189.00) Cross-site scripting (XSS) vulnerabilities (BEA)
- BEA Security Advisory (BEA08-190.00) A WebLogic Portal Administration Console se (BEA Systems)
- BEA Security Advisory (BEA08-191.00) Tampering HTML request headers could lead t (BEA)
- BEA Security Advisory (BEA08-192.00) When content portlets are deleted from one (BEA Systems)
- BEA Security Advisory (BEA08-193.00) Non-authorized user may be able to receive (BEA)
- BEA Security Advisory (BEA08-194.00) A non-authorized user may be able to send (BEA Systems)
- BEA Security Advisory (BEA08-195.00) Cross-site scripting vulnerability in Conso (BEA Systems)
- BEA Security Advisory (BEA08-196.00) A session fixation exploit could result in (BEA Systems)
- BEA Security Advisory (BEA08-197.00) Account lockout can be bypassed, exposing t (BEA Systems)
- BEA Security Advisory (BEA08-199.00) A carefully constructed URL may cause the S (BEA Systems)
- BEA Security Advisory (BEA08-200.00) Server files can be accessed by a remote us (BEA Systems)
- Infinite invalid authentication attempts possible in BEA WebLogic Server (S21Sec)