Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
BID:43931
Info
Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
| Bugtraq ID: | 43931 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Oct 12 2010 12:00AM |
| Credit: | Carl Livitt of Stach and Liu, LLC |
| Vulnerable: |
Oracle Weblogic Server 10.3.3 |
| Not Vulnerable: | |
Discussion
Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
Oracle WebLogic Server Node Manager is prone to a remote security vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow a remote attacker to gain unauthorized access and execute malicious commands on the vulnerable server. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
Oracle WebLogic Server Node Manager 10.3.3 is vulnerable; other versions may also be affected.
Oracle WebLogic Server Node Manager is prone to a remote security vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow a remote attacker to gain unauthorized access and execute malicious commands on the vulnerable server. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
Oracle WebLogic Server Node Manager 10.3.3 is vulnerable; other versions may also be affected.
Exploit / POC
Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle WebLogic Server Node Manager UNC Path Remote Security Vulnerability
References:
References: