Description
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected products
- oracle / bea_product_suite7.0 – 7.0
- oracle / bea_product_suite8.1 – 8.1
- oracle / bea_product_suite9.0 – 9.0
- oracle / bea_product_suite9.1 – 9.1
- oracle / bea_product_suite9.2 – 9.2
- oracle / bea_product_suite10.0 – 10.0
- oracle / bea_product_suite10.3 – 10.3
Exploits & proofs of concept
- exploit-dbBEA WebLogic - JSESSIONID Cookie Value Overflow (Metasploit)by Metasploit
- exploit-dbOracle WebLogic IIS connector JSESSIONID - Remote Overflowby Guido Landi
References
Updated 16m ago · 8 sources