// For flags

CVE-2008-3257

Bea Weblogic Apache Connector - Code Execution / Denial of Service

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.

Desbordamiento de búfer basado en pila en Apache Connector (mod_wl) en Oracle WebLogic Server (anteriormente BEA Weblogic Server) 10.3 y anteriores, permite a atacantes remotos ejecutar código de su elección a través de una cadena larga HTTP, como se ha demostrado mediante una cadena después del "POST /.jsp" en una petición HTTP. NOTA: es probable que esta vulnerabilidad se solape con el CVE-2008-2579 u otra vulnerabilidad revelada en los avisos de Oracle CPUJul2008.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-07-22 CVE Reserved
  • 2008-07-22 CVE Published
  • 2012-05-19 First Exploit
  • 2024-06-22 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
3.1.8
Search vendor "Bea" for product "Weblogic Server" and version "3.1.8"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.0
Search vendor "Bea" for product "Weblogic Server" and version "4.0"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.0.4
Search vendor "Bea" for product "Weblogic Server" and version "4.0.4"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5
Search vendor "Bea" for product "Weblogic Server" and version "4.5"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5.1
Search vendor "Bea" for product "Weblogic Server" and version "4.5.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5.1
Search vendor "Bea" for product "Weblogic Server" and version "4.5.1"
sp15
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5.2
Search vendor "Bea" for product "Weblogic Server" and version "4.5.2"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5.2
Search vendor "Bea" for product "Weblogic Server" and version "4.5.2"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
4.5.2
Search vendor "Bea" for product "Weblogic Server" and version "4.5.2"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp10
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp11
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp12
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp13
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp5
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp6
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp7
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp8
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
5.1
Search vendor "Bea" for product "Weblogic Server" and version "5.1"
sp9
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.0
Search vendor "Bea" for product "Weblogic Server" and version "6.0"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.0
Search vendor "Bea" for product "Weblogic Server" and version "6.0"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.0
Search vendor "Bea" for product "Weblogic Server" and version "6.0"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.0
Search vendor "Bea" for product "Weblogic Server" and version "6.0"
sp6
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp5
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp6
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp7
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
6.1
Search vendor "Bea" for product "Weblogic Server" and version "6.1"
sp8
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp5
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp6
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0
Search vendor "Bea" for product "Weblogic Server" and version "7.0"
sp7
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0.0.1
Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0.0.1
Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0.0.1
Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0.0.1
Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
7.0.0.1
Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp5
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
8.1
Search vendor "Bea" for product "Weblogic Server" and version "8.1"
sp6
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
ga
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
sp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
sp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
sp3
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
sp4
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.0
Search vendor "Bea" for product "Weblogic Server" and version "9.0"
sp5
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.1
Search vendor "Bea" for product "Weblogic Server" and version "9.1"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.1
Search vendor "Bea" for product "Weblogic Server" and version "9.1"
ga
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.2
Search vendor "Bea" for product "Weblogic Server" and version "9.2"
-
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.2
Search vendor "Bea" for product "Weblogic Server" and version "9.2"
mp1
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
9.2
Search vendor "Bea" for product "Weblogic Server" and version "9.2"
mp2
Affected
Bea
Search vendor "Bea"
Weblogic Server
Search vendor "Bea" for product "Weblogic Server"
10.0
Search vendor "Bea" for product "Weblogic Server" and version "10.0"
-
Affected
Bea Systems
Search vendor "Bea Systems"
Apache Connector In Weblogic Server
Search vendor "Bea Systems" for product "Apache Connector In Weblogic Server"
*-
Affected
Bea Systems
Search vendor "Bea Systems"
Weblogic Server
Search vendor "Bea Systems" for product "Weblogic Server"
10.0_mp1
Search vendor "Bea Systems" for product "Weblogic Server" and version "10.0_mp1"
-
Affected
Oracle
Search vendor "Oracle"
Weblogic Server
Search vendor "Oracle" for product "Weblogic Server"
<= 10.3
Search vendor "Oracle" for product "Weblogic Server" and version " <= 10.3"
-
Affected