Multiple BEA WebLogic Server/Express Vulnerabilities
BID:8143
Info
Multiple BEA WebLogic Server/Express Vulnerabilities
| Bugtraq ID: | 8143 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 08 2003 12:00AM |
| Updated: | Jul 08 2003 12:00AM |
| Credit: | These vulnerabilities were announced by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 2 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems WebLogic Server for Win32 6.1 SP 4 BEA Systems WebLogic Server for Win32 6.1 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 2 BEA Systems WebLogic Server for Win32 6.1 SP 1 BEA Systems WebLogic Server for Win32 6.1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 2 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express for Win32 6.1 SP 5 BEA Systems WebLogic Express for Win32 6.1 SP 4 BEA Systems WebLogic Express for Win32 6.1 SP 3 BEA Systems WebLogic Express for Win32 6.1 SP 2 BEA Systems WebLogic Express for Win32 6.1 SP 1 BEA Systems WebLogic Express for Win32 6.1 BEA Systems WebLogic Express 8.1 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 BEA Systems WebLogic Express 6.1 SP 5 BEA Systems WebLogic Express 6.1 SP 4 BEA Systems WebLogic Express 6.1 SP 3 BEA Systems WebLogic Express 6.1 SP 2 BEA Systems WebLogic Express 6.1 SP 1 BEA Systems WebLogic Express 6.1 |
| Not Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 SP 3 BEA Systems WebLogic Server for Win32 6.1 SP 5 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 SP 3 BEA Systems WebLogic Express for Win32 6.1 SP 5 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 SP 3 BEA Systems WebLogic Express 7.0 SP 3 BEA Systems WebLogic Express 6.1 SP 5 |
Discussion
Multiple BEA WebLogic Server/Express Vulnerabilities
BEA Systems has released patches for multiple vulnerabilities in various versions of BEA WebLogic Server and Express. Exploitation of these issues could result in unauthorized access or disclosure of sensitive information.
BEA Systems has released patches for multiple vulnerabilities in various versions of BEA WebLogic Server and Express. Exploitation of these issues could result in unauthorized access or disclosure of sensitive information.
Exploit / POC
Multiple BEA WebLogic Server/Express Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple BEA WebLogic Server/Express Vulnerabilities
Solution:
The vendor has released fixes that address these issues.
(CR105624_70sp2.jar) fixes the unauthorized access to the console issue for WebLogic Server/Express 7.0 and 7.0.0.1.
(CR105809_81_ga.jar and CR105809_70sp2.jar) fix the operators administrative access issue on WebLogic Server/Express 8.1 and WebLogic Server/Express 7.0/7.0.0.1 respectively.
(CR093813_70sp2.zip and CR093813_61sp5.zip) fix the prevent protect password issue on WebLogic Server/Express 7.0/7.0.0.1 and WebLogic Server/Express 6.1 respectively.
These fixes will be bundled into pending service packs for the various releases. Users are advised to apply all fixes for any vulnerable versions they are running.
BEA Systems Weblogic Server 6.1 SP 5
BEA Systems WebLogic Express 6.1 SP 5
BEA Systems WebLogic Server for Win32 6.1 SP 5
BEA Systems WebLogic Express for Win32 6.1 SP 5
BEA Systems WebLogic Express 7.0 SP 2
BEA Systems Weblogic Server 7.0 .0.1 SP 2
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2
BEA Systems Weblogic Server 7.0 SP 2
BEA Systems Weblogic Server 7.0
BEA Systems WebLogic Express 7.0 .0.1 SP 2
BEA Systems WebLogic Express for Win32 7.0
BEA Systems WebLogic Express for Win32 7.0 SP 2
BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2
BEA Systems WebLogic Server for Win32 7.0 SP 2
BEA Systems Weblogic Server 8.1
BEA Systems WebLogic Express 8.1
Solution:
The vendor has released fixes that address these issues.
(CR105624_70sp2.jar) fixes the unauthorized access to the console issue for WebLogic Server/Express 7.0 and 7.0.0.1.
(CR105809_81_ga.jar and CR105809_70sp2.jar) fix the operators administrative access issue on WebLogic Server/Express 8.1 and WebLogic Server/Express 7.0/7.0.0.1 respectively.
(CR093813_70sp2.zip and CR093813_61sp5.zip) fix the prevent protect password issue on WebLogic Server/Express 7.0/7.0.0.1 and WebLogic Server/Express 6.1 respectively.
These fixes will be bundled into pending service packs for the various releases. Users are advised to apply all fixes for any vulnerable versions they are running.
BEA Systems Weblogic Server 6.1 SP 5
-
BEA Systems CR093813_61sp5.zip
Upgrade to Service Pack 5 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_61sp5.zip
BEA Systems WebLogic Express 6.1 SP 5
-
BEA Systems CR093813_61sp5.zip
Upgrade to Service Pack 5 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_61sp5.zip
BEA Systems WebLogic Server for Win32 6.1 SP 5
-
BEA Systems CR093813_61sp5.zip
Upgrade to Service Pack 5 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_61sp5.zip
BEA Systems WebLogic Express for Win32 6.1 SP 5
-
BEA Systems CR093813_61sp5.zip
Upgrade to Service Pack 5 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_61sp5.zip
BEA Systems WebLogic Express 7.0 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems Weblogic Server 7.0 .0.1 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems Weblogic Server 7.0 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems Weblogic Server 7.0
-
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Express 7.0 .0.1 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Express for Win32 7.0
-
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Express for Win32 7.0 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems WebLogic Server for Win32 7.0 SP 2
-
BEA Systems CR093813_70sp2.zip
Upgrade to Service Pack 2 and follow the instructions included in the zip file.
ftp://ftpna.beasys.com/pub/releases/security/CR093813_70sp2.zip -
BEA Systems CR105809_70sp2.jar
Upgrade to Service Pack 2 and apply the patch
ftp://ftpna.beasys.com/pub/releases/security/CR105809_70sp2.jar -
BEA Systems CR105624_70sp2.jar
Upgrade to Service Pack 2, and apply the following patch.
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
BEA Systems Weblogic Server 8.1
-
BEA Systems CR105809_81_ga.jar
ftp://ftpna.beasys.com/pub/releases/security/CR105809_81_ga.jar
BEA Systems WebLogic Express 8.1
-
BEA Systems CR105809_81_ga.jar
ftp://ftpna.beasys.com/pub/releases/security/CR105809_81_ga.jar
References
Multiple BEA WebLogic Server/Express Vulnerabilities
References:
References:
- SECURITY ADVISORY (BEA03-33.00) (BEA Systems)
- SECURITY ADVISORY (BEA03-32.00) (BEA Systems)
- SECURITY ADVISORY (BEA03-34.00) (BEA Systems)