BEA WebLogic Web Application Authentication Bypass Vulnerability
BID:7130
Info
BEA WebLogic Web Application Authentication Bypass Vulnerability
| Bugtraq ID: | 7130 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2003 12:00AM |
| Updated: | Mar 18 2003 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 |
| Not Vulnerable: |
BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 SP 2 |
Discussion
BEA WebLogic Web Application Authentication Bypass Vulnerability
BEA WebLogic reported vulnerable to authentication bypass vulnerability under certain circumstances.
When a BEA WebLogic web application component that implements session persistence is redistributed without a server reboot an authenticated user session can, in some cases, be reused by any user for a variable period of time without requiring valid credentials.
This vulnerability may be exploited to gain access to the WebLogic server without prior authentication.
BEA WebLogic reported vulnerable to authentication bypass vulnerability under certain circumstances.
When a BEA WebLogic web application component that implements session persistence is redistributed without a server reboot an authenticated user session can, in some cases, be reused by any user for a variable period of time without requiring valid credentials.
This vulnerability may be exploited to gain access to the WebLogic server without prior authentication.
Exploit / POC
BEA WebLogic Web Application Authentication Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
BEA WebLogic Web Application Authentication Bypass Vulnerability
Solution:
BEA Systems have advised that users upgrade to the latest service pack levels that address this issue:
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems Weblogic Server 7.0 .0.1 SP 1
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems Weblogic Server 7.0
Solution:
BEA Systems have advised that users upgrade to the latest service pack levels that address this issue:
BEA Systems Weblogic Server 7.0 .0.1
-
BEA Systems WebLogic Server 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0 .0.1 SP 1
-
BEA Systems WebLogic Server 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0 SP 1
-
BEA Systems WebLogic Server 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0
-
BEA Systems WebLogic Server 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
References
BEA WebLogic Web Application Authentication Bypass Vulnerability
References:
References:
- SECURITY ADVISORY (BEA03-27.00) (BEA Systems)