BEA WebLogic Server and Express Inadvertent Security Removal Weakness
BID:5846
Info
BEA WebLogic Server and Express Inadvertent Security Removal Weakness
| Bugtraq ID: | 5846 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2002 12:00AM |
| Updated: | Oct 01 2002 12:00AM |
| Credit: | This issue was publicized in a BEA Systems security advisory. |
| Vulnerable: |
BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: |
BEA Systems Weblogic Server 7.0 SP 1 BEA Systems WebLogic Express 7.0 SP 1 |
Discussion
BEA WebLogic Server and Express Inadvertent Security Removal Weakness
Under some circumstances, BEA WebLogic Server and Express are prone to a weakness which may inadvertently cause security constraints to be removed.
This issue occurs when applications containing Servlets or EJBs are deployed on multiple servers. When such an application is undeployed from one server, the specified security constraints and role mappings for Servlets or EJBs will be removed on all servers. The consequence of this weakness is that all Servlets or EJBs will be left exposed.
Under some circumstances, BEA WebLogic Server and Express are prone to a weakness which may inadvertently cause security constraints to be removed.
This issue occurs when applications containing Servlets or EJBs are deployed on multiple servers. When such an application is undeployed from one server, the specified security constraints and role mappings for Servlets or EJBs will be removed on all servers. The consequence of this weakness is that all Servlets or EJBs will be left exposed.
Exploit / POC
BEA WebLogic Server and Express Inadvertent Security Removal Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BEA WebLogic Server and Express Inadvertent Security Removal Weakness
Solution:
Fixes are available:
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems Weblogic Server 7.0
BEA Systems WebLogic Express 7.0
BEA Systems WebLogic Express 7.0 .0.1
Solution:
Fixes are available:
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems Weblogic Server 7.0
BEA Systems WebLogic Express 7.0
BEA Systems WebLogic Express 7.0 .0.1
References
BEA WebLogic Server and Express Inadvertent Security Removal Weakness
References:
References:
- SECURITY ADVISORY (BEA02-21.00) (BEA Systems)