Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
BID:30273
Info
Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 30273 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3257 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2008 12:00AM |
| Updated: | Nov 20 2008 07:14PM |
| Credit: | KingCope |
| Vulnerable: |
Oracle mod_wl 0 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 9.2 Maintenance Pack BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 10.0 MP1 BEA Systems Weblogic Server 10.0 BEA Systems WebLogic Express 8.1 SP 5 BEA Systems WebLogic Express 8.1 SP 4 BEA Systems WebLogic Express 8.1 SP 3 BEA Systems WebLogic Express 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 .0.1 SP 4 BEA Systems WebLogic Express 7.0 .0.1 SP 3 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 SP 7 BEA Systems WebLogic Express 7.0 SP 6 BEA Systems WebLogic Express 7.0 SP 5 BEA Systems WebLogic Express 7.0 SP 4 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 6.1 SP 7 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 9.2 BEA Systems WebLogic Express 9.1 BEA Systems WebLogic Express 9.0 BEA Systems WebLogic Express 8.1.0 SP 6 BEA Systems WebLogic Express 10.0 |
| Not Vulnerable: |
BEA Systems Weblogic Server 10.3 BEA Systems WebLogic Express 10.3 |
Discussion
Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
Oracle mod_wl (formerly BEA mod_wl) is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Oracle mod_wl (formerly BEA mod_wl) is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept and exploit code are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept and exploit code are available:
Solution / Fix
Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
BEA Systems Weblogic Server 9.2
BEA Systems Weblogic Server 9.0
BEA Systems Weblogic Server 9.1
BEA Systems WebLogic Express 9.2
BEA Systems WebLogic Express 10.0
BEA Systems Weblogic Server 10.0
BEA Systems WebLogic Express 9.0
BEA Systems Weblogic Server 10.0 MP1
BEA Systems WebLogic Express 9.1
BEA Systems WebLogic Express 8.1.0 SP 6
BEA Systems WebLogic Express 6.1 SP 3
BEA Systems Weblogic Server 6.1 SP 5
BEA Systems Weblogic Server 6.1 SP 4
BEA Systems WebLogic Express 6.1 SP 5
BEA Systems Weblogic Server 6.1 SP 3
BEA Systems WebLogic Express 6.1 SP 4
BEA Systems WebLogic Express 6.1 SP 7
BEA Systems Weblogic Server 6.1 SP 7
BEA Systems Weblogic Server 6.1 SP 2
BEA Systems Weblogic Server 6.1 SP 1
BEA Systems WebLogic Express 6.1 SP 2
BEA Systems WebLogic Express 6.1 SP 1
BEA Systems WebLogic Express 7.0 SP 2
BEA Systems Weblogic Server 7.0 SP 3
BEA Systems Weblogic Server 7.0 SP 4
BEA Systems WebLogic Express 7.0 SP 5
BEA Systems Weblogic Server 7.0 SP 7
BEA Systems Weblogic Server 7.0 SP 2
BEA Systems Weblogic Server 7.0 SP 6
BEA Systems WebLogic Express 7.0 SP 6
BEA Systems Weblogic Server 7.0 SP 5
BEA Systems WebLogic Express 7.0 SP 3
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems WebLogic Express 7.0 SP 7
BEA Systems WebLogic Express 7.0 SP 4
BEA Systems WebLogic Express 7.0 SP 1
BEA Systems Weblogic Server 8.1 SP 6
BEA Systems Weblogic Server 8.1 SP 1
BEA Systems WebLogic Express 8.1 SP 5
BEA Systems Weblogic Server 8.1 SP 2
BEA Systems Weblogic Server 8.1 SP 3
BEA Systems Weblogic Server 8.1 SP 4
BEA Systems WebLogic Express 8.1 SP 4
BEA Systems WebLogic Express 8.1 SP 2
BEA Systems WebLogic Express 8.1 SP 3
BEA Systems Weblogic Server 8.1 SP 5
BEA Systems WebLogic Express 8.1 SP 1
BEA Systems WebLogic Express 8.1
Solution:
The vendor has released an update. Please see the references for more information.
BEA Systems Weblogic Server 9.2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 9.0
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 9.1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 9.2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 10.0
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 10.0
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 9.0
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 10.0 MP1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 9.1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1.0 SP 6
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 7
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 7
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 6.1 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 6.1 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 7
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 6
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 6
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 7.0 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 7
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 7.0 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 6
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1 SP 4
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1 SP 2
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1 SP 3
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems Weblogic Server 8.1 SP 5
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1 SP 1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
BEA Systems WebLogic Express 8.1
-
BEA Systems WLSWebServerPlugins1.0.1136334-Apache.zip
ftp://anonymous:dev2dev%40bea%[email protected]/pub/releases/securit y/WLSWebServerPlugins1.0.1136334-Apache.zip
References
Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability
References:
References:
- ModSecurity Homepage (Breach Security)
- Oracle mod_wl Homepage (Oracle)
- WebLogic Server Product Homepage (Oracle)
- SECURITY ADVISORY (CVE-2008-3257) (Oracle)
- Vulnerability Note VU#716387 (US-CERT)