|
BEA WebLogic Server / Express Unauthorised Console Access Vulnerability
|
|
Secunia Advisory:
|
SA9231
|
|
|
Release Date:
|
2003-07-11
|
|
Popularity:
|
6,899 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | BEA WebLogic Express 7.x BEA WebLogic Server 7.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: A vulnerability has been identified in BEA WebLogic Server and Express, which can be exploited by malicious people to gain unautorised access to the console.
The problem is that it is possible to gain access to console through the managed server's listen port when MSI (Managed Server Independence) is used and a firewall or content filter restricts access to the console.
The vulnerablity affects the following versions:
- WebLogic Server and Express 7.0 and 7.0.0.1 (all platforms)
Solution: Apply patch (requires SP2):
ftp://ftpna.beasys.com/pub/releases/security/CR105624_70sp2.jar
Original Advisory: http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-32.jsp
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|