Oracle WebLogic Server Administration Console HTML Injection Vulnerability
BID:36766
Info
Oracle WebLogic Server Administration Console HTML Injection Vulnerability
| Bugtraq ID: | 36766 |
| Class: | Unknown |
| CVE: |
CVE-2009-3396 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2009 12:00AM |
| Updated: | Nov 02 2009 09:27PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Weblogic Server 9.2 MP3 Oracle Weblogic Server 9.2 MP2 Oracle Weblogic Server 9.2 MP1 Oracle Weblogic Server 9.2 Oracle Weblogic Server 9.1 GA Oracle Weblogic Server 9.0 GA Oracle Weblogic Server 10.3 Oracle Weblogic Server 10.0 MP1 Oracle Weblogic Server 10 |
| Not Vulnerable: | |
Discussion
Oracle WebLogic Server Administration Console HTML Injection Vulnerability
Oracle WebLogic Server is prone to an HTML Injection Vulnerability. This issue occurs in the Web Administration Console.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'WLS Console' privileges.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser,
potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This vulnerability affects the following supported versions:
9.0
9.1
9.2.3
10.0.1
10.3
Oracle WebLogic Server is prone to an HTML Injection Vulnerability. This issue occurs in the Web Administration Console.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'WLS Console' privileges.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser,
potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This vulnerability affects the following supported versions:
9.0
9.1
9.2.3
10.0.1
10.3
Exploit / POC
Oracle WebLogic Server Administration Console HTML Injection Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Oracle WebLogic Server Administration Console HTML Injection Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
Oracle WebLogic Server Administration Console HTML Injection Vulnerability
References:
References: