Bea Systems WebLogic ResourceAllocationException System Password Disclosure Vulnerability
BID:6586
Info
Bea Systems WebLogic ResourceAllocationException System Password Disclosure Vulnerability
| Bugtraq ID: | 6586 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2003 12:00AM |
| Updated: | Jan 11 2003 12:00AM |
| Credit: | Vulnerability announced by BEA Systems. |
| Vulnerable: |
BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 |
| Not Vulnerable: |
BEA Systems Weblogic Server 6.1 SP 4 |
Exploit / POC
Bea Systems WebLogic ResourceAllocationException System Password Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Bea Systems WebLogic ResourceAllocationException System Password Disclosure Vulnerability
Solution:
Revisions 6.1, 6.1 Service Pack 1, 6.1 Service Pack 2, and 6.1 Service Pack 3 should upgrade to 6.1 Service Pack 4.
Revisions 7.0 Service Pack 1, and 7.0.0.1 require upgrading to 7.0 Service Pack 1 before applying the available patch.
The vendor has made fixes available:
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems Weblogic Server 7.0
Solution:
Revisions 6.1, 6.1 Service Pack 1, 6.1 Service Pack 2, and 6.1 Service Pack 3 should upgrade to 6.1 Service Pack 4.
Revisions 7.0 Service Pack 1, and 7.0.0.1 require upgrading to 7.0 Service Pack 1 before applying the available patch.
The vendor has made fixes available:
BEA Systems Weblogic Server 7.0 .0.1
-
BEA Systems CR093060_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR093060_70sp1.jar
BEA Systems Weblogic Server 7.0 SP 1
-
BEA Systems CR093060_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR093060_70sp1.jar
BEA Systems Weblogic Server 7.0
-
BEA Systems CR093060_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR093060_70sp1.jar
References
Bea Systems WebLogic ResourceAllocationException System Password Disclosure Vulnerability
References:
References:
- SECURITY ADVISORY (BEA03-24.00) (BEA Systems)