BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
BID:7131
Info
BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
| Bugtraq ID: | 7131 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2003 12:00AM |
| Updated: | Mar 18 2003 12:00AM |
| Credit: | Vulnerability disclosed by BEA Systems. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: |
BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 SP 2 |
Discussion
BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
It has been reported that BEA Systems WebLogic allows the performance of some unauthorized functions in the JNDI tree by users. Because of this, an attacker may be able to destroy data, and potentially cause a denial of service.
It has been reported that BEA Systems WebLogic allows the performance of some unauthorized functions in the JNDI tree by users. Because of this, an attacker may be able to destroy data, and potentially cause a denial of service.
Exploit / POC
BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
Solution:
Fixed versions available:
BEA Systems WebLogic Express 7.0 .0.1
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems WebLogic Express 7.0 .0.1 SP 1
BEA Systems Weblogic Server 7.0 .0.1 SP 1
BEA Systems WebLogic Express 7.0
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems Weblogic Server 7.0
BEA Systems WebLogic Express 7.0 SP 1
Solution:
Fixed versions available:
BEA Systems WebLogic Express 7.0 .0.1
-
BEA Systems WebLogic Express 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0 .0.1
-
BEA Systems WebLogic Server 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems WebLogic Express 7.0 .0.1 SP 1
-
BEA Systems WebLogic Express 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0 .0.1 SP 1
-
BEA Systems WebLogic Server 7.0.0.1 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems WebLogic Express 7.0
-
BEA Systems WebLogic Express 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0 SP 1
-
BEA Systems WebLogic Server 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems Weblogic Server 7.0
-
BEA Systems WebLogic Server 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
BEA Systems WebLogic Express 7.0 SP 1
-
BEA Systems WebLogic Express 7.0 SP2
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
References
BEA Systems WebLogic JNDI Tree Modify Access Vulnerability
References:
References:
- SECURITY ADVISORY (BEA03-29.00) (BEA Systems)