|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2008-10

Vulnerability in Oracle WebLogic plug-in for Apache causes Denial of Service

Original Issue Date: October 15, 2008

Severity Rating: High

Systems Affected

  • Oracle WebLogic Server 9.0,9.1,10.3
  • Oracle WebLogic Server 10.0 released through Maintenance Pack 1
  • Oracle WebLogic Server 9.2 released through Maintenance Pack 3
  • Oracle WebLogic Server 8.1 released through Service Pack 6
  • Oracle WebLogic Server 7.0 released through Service Pack 7
  • Oracle WebLogic Server 6.1 released through Service Pack 7

Overview

A vulnerability has been reported in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7, which could be exploited by remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

Description

A vulnerability has been reported in certain versions of WebLogic Server. This vulnerability can be remotely exploited without authentication to affect the availability, confidentiality or integrity of WebLogic Server applications which use the Apache web server configured with the Oracle WebLogic plug-in for Apache.

Workarounds

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

Oracle

http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html

http://blogs.oracle.com/security/2008/10/14

https://support.bea.com/application_content/product_portlets/
securityadvisories/index.html

CVE-Name


CVE-2008-4008

References

BEA
https://support.bea.com/application_content/product_portlets/
securityadvisories/2806.html

Security Database
http://www.security-database.com/cvss.php?alert=CVE-2008-4008

SecurityTracker
http://www.securitytracker.com/alerts/2008/Oct/1021056.html

Security Lab
http://en.securitylab.ru/nvd/361224.php

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed