BEA WebLogic Internal Servlet Input Validation Vulnerabilities
BID:7122
Info
BEA WebLogic Internal Servlet Input Validation Vulnerabilities
| Bugtraq ID: | 7122 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Mar 17 2003 12:00AM |
| Credit: | Discovery is credited to "Lluis Mora" <[email protected]>. |
| Vulnerable: |
BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems Weblogic Server 6.0 SP 2 BEA Systems Weblogic Server 6.0 SP 1 BEA Systems Weblogic Server 6.0 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Internal Servlet Input Validation Vulnerabilities
Input validation issues have been reported in a WebLogic internal servlet that is used by the web management interface. Unauthenticated users may exploit these issues in the internal servlet to upload malicious files to a host running the vulnerable software or disclose the contents of sensitive files. This could result in execution of arbitrary commands or other attacks.
These issues were reported to affect BEA WebLogic Server. BEA WebLogic Express may also be affected, so users of WebLogic Express are also advised to apply the provided patches.
Input validation issues have been reported in a WebLogic internal servlet that is used by the web management interface. Unauthenticated users may exploit these issues in the internal servlet to upload malicious files to a host running the vulnerable software or disclose the contents of sensitive files. This could result in execution of arbitrary commands or other attacks.
These issues were reported to affect BEA WebLogic Server. BEA WebLogic Express may also be affected, so users of WebLogic Express are also advised to apply the provided patches.
Exploit / POC
BEA WebLogic Internal Servlet Input Validation Vulnerabilities
There is no exploit required.
There is no exploit required.
Solution / Fix
BEA WebLogic Internal Servlet Input Validation Vulnerabilities
Solution:
BEA Systems has released fixes which address this issue. Further instructions on applying fixes may be found in the attached BEA advisory.
BEA Systems Weblogic Server 6.0 SP 2
BEA Systems Weblogic Server 6.1 SP 4
BEA Systems Weblogic Server 7.0 SP 2
Solution:
BEA Systems has released fixes which address this issue. Further instructions on applying fixes may be found in the attached BEA advisory.
BEA Systems Weblogic Server 6.0 SP 2
-
BEA Systems CR096950_60sp2rp3.zip
WebLogic Server and Express 6.0 Service Pack 2 Rolling Patch 3 for Windows.
ftp://ftpna.beasys.com/pub/releases/security/CR096950_60sp2rp3.zip
BEA Systems Weblogic Server 6.1 SP 4
-
BEA Systems CR096950_61sp4.zip
WebLogic Server and Express 6.1 Service Pack 4 patch for Windows.
ftp://ftpna.beasys.com/pub/releases/security/CR096950_61sp4.zip
BEA Systems Weblogic Server 7.0 SP 2
-
BEA Systems CR096950_70sp2.zip
WebLogic Server and Express 7.0/7.0.0.1 Service Pack 2 patch for Windows.
ftp://ftpna.beasys.com/pub/releases/security/CR096950_70sp2.zip
References
BEA WebLogic Internal Servlet Input Validation Vulnerabilities
References:
References:
- SECURITY ADVISORY (BEA03-28.00) (BEA Systems)
- S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server ("Lluis Mora"
)