CVE-2008-5457
BEA WebLogic - JSESSIONID Cookie Value Overflow
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerabilidad no especificada en el componente Oracle BEA WebLogic Server Plugins para Apache, Sun y IIS web servers en BEA Product Suite 10.3, 10.0, MP1, 9.2, MP3, 9.1, 9.0, 8.1, SP6, 7.0 y SP7 permite a atacantes remotos afectar la confidencialidad, integridad y disponibilidad mediante vectores desconocidos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-12-11 CVE Reserved
- 2009-01-14 CVE Published
- 2009-04-01 First Exploit
- 2024-08-07 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/33526 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/33177 | Vdb Entry | |
http://www.securitytracker.com/id?1021571 | Vdb Entry | |
http://www.vupen.com/english/advisories/2009/0115 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16762 | 2010-07-03 | |
https://www.exploit-db.com/exploits/8336 | 2009-04-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 7.0 Search vendor "Oracle" for product "Bea Product Suite" and version "7.0" | sp7 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 8.1 Search vendor "Oracle" for product "Bea Product Suite" and version "8.1" | sp6 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 9.0 Search vendor "Oracle" for product "Bea Product Suite" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 9.1 Search vendor "Oracle" for product "Bea Product Suite" and version "9.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 9.2 Search vendor "Oracle" for product "Bea Product Suite" and version "9.2" | mp3 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 10.0 Search vendor "Oracle" for product "Bea Product Suite" and version "10.0" | mp1 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Bea Product Suite Search vendor "Oracle" for product "Bea Product Suite" | 10.3 Search vendor "Oracle" for product "Bea Product Suite" and version "10.3" | - |
Affected
|