Vulnerability Name: CVE-2008-2579 (CCN-43823) Assigned: 2008-07-15 Published: 2008-07-15 Updated: 2020-10-14 Summary: Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors. CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2008-2579 Source: HP Type: Broken LinkSSRT061201 Source: JVN Type: Third Party AdvisoryJVN#81667751 Source: JVNDB Type: Third Party Advisory, VDB EntryJVNDB-2008-000040 Source: CCN Type: SA31087Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory31087 Source: CCN Type: SA31113HP Oracle for OpenView Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory31113 Source: CCN Type: SECTRACK ID: 1020498Oracle WebLogic Server Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions Source: CCN Type: Oracle Critical Patch Update - July 2008Oracle Critical Patch Update Advisory - July 2008 Source: CONFIRM Type: Broken Linkhttp://www.oracle.com/technetwork/topics/security/cpujul2008-090335.html Source: CCN Type: BID-30177Oracle July 2008 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry1020498 Source: VUPEN Type: Third Party AdvisoryADV-2008-2109 Source: VUPEN Type: Third Party AdvisoryADV-2008-2115 Source: XF Type: Third Party Advisory, VDB Entryoracle-weblogic-plugins-unauth-access(43823) Source: XF Type: UNKNOWNoracle-weblogic-plugins-unauth-access(43823) Source: CCN Type: BEA Support Web siteInformation disclosure vulnerability in WebLogic plug-ins for Apache, Sun and IIS Web servers Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:weblogic_server:6.1:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp1:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp1:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp1:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp2:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp2:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp2:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp4:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp4:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp4:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp5:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp5:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp5:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp6:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp6:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp6:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp7:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp7:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:6.1:sp7:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp1:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp1:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp1:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp2:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp2:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp2:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp4:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp4:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp4:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp5:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp5:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp5:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp6:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp6:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp6:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp7:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp7:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:7.0:sp7:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp1:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp1:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp1:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp2:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp2:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp2:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp4:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp4:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp4:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp5:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp5:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp5:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp6:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp6:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:8.1:sp6:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.0:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.0:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.0:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.0:maintenance_pack3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.0:maintenance_pack3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.0:maintenance_pack3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.1:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.1:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.1:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.1:maintenance_pack3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.1:maintenance_pack3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.1:maintenance_pack3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.2:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.2:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.2:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack1:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack1:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack1:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack2:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack2:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack2:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack3:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack3:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:9.2:maintenance_pack3:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:10.0:-:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:10.0:-:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:10.0:-:*:*:*:sun:*:* OR cpe:/a:oracle:weblogic_server:10.0:maintenance_pack1:*:*:*:apache:*:* OR cpe:/a:oracle:weblogic_server:10.0:maintenance_pack1:*:*:*:internet_information_services:*:* OR cpe:/a:oracle:weblogic_server:10.0:maintenance_pack1:*:*:*:sun:*:* Configuration CCN 1 :cpe:/a:oracle:weblogic_server:9.0:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:9.1:*:*:*:*:*:*:* OR cpe:/a:oracle:weblogic_server:9.2.0.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle weblogic server 6.1 -
oracle weblogic server 6.1 -
oracle weblogic server 6.1 -
oracle weblogic server 6.1 sp1
oracle weblogic server 6.1 sp1
oracle weblogic server 6.1 sp1
oracle weblogic server 6.1 sp2
oracle weblogic server 6.1 sp2
oracle weblogic server 6.1 sp2
oracle weblogic server 6.1 sp3
oracle weblogic server 6.1 sp3
oracle weblogic server 6.1 sp3
oracle weblogic server 6.1 sp4
oracle weblogic server 6.1 sp4
oracle weblogic server 6.1 sp4
oracle weblogic server 6.1 sp5
oracle weblogic server 6.1 sp5
oracle weblogic server 6.1 sp5
oracle weblogic server 6.1 sp6
oracle weblogic server 6.1 sp6
oracle weblogic server 6.1 sp6
oracle weblogic server 6.1 sp7
oracle weblogic server 6.1 sp7
oracle weblogic server 6.1 sp7
oracle weblogic server 7.0 -
oracle weblogic server 7.0 -
oracle weblogic server 7.0 -
oracle weblogic server 7.0 sp1
oracle weblogic server 7.0 sp1
oracle weblogic server 7.0 sp1
oracle weblogic server 7.0 sp2
oracle weblogic server 7.0 sp2
oracle weblogic server 7.0 sp2
oracle weblogic server 7.0 sp3
oracle weblogic server 7.0 sp3
oracle weblogic server 7.0 sp3
oracle weblogic server 7.0 sp4
oracle weblogic server 7.0 sp4
oracle weblogic server 7.0 sp4
oracle weblogic server 7.0 sp5
oracle weblogic server 7.0 sp5
oracle weblogic server 7.0 sp5
oracle weblogic server 7.0 sp6
oracle weblogic server 7.0 sp6
oracle weblogic server 7.0 sp6
oracle weblogic server 7.0 sp7
oracle weblogic server 7.0 sp7
oracle weblogic server 7.0 sp7
oracle weblogic server 8.1 -
oracle weblogic server 8.1 -
oracle weblogic server 8.1 -
oracle weblogic server 8.1 sp1
oracle weblogic server 8.1 sp1
oracle weblogic server 8.1 sp1
oracle weblogic server 8.1 sp2
oracle weblogic server 8.1 sp2
oracle weblogic server 8.1 sp2
oracle weblogic server 8.1 sp3
oracle weblogic server 8.1 sp3
oracle weblogic server 8.1 sp3
oracle weblogic server 8.1 sp4
oracle weblogic server 8.1 sp4
oracle weblogic server 8.1 sp4
oracle weblogic server 8.1 sp5
oracle weblogic server 8.1 sp5
oracle weblogic server 8.1 sp5
oracle weblogic server 8.1 sp6
oracle weblogic server 8.1 sp6
oracle weblogic server 8.1 sp6
oracle weblogic server 9.0 -
oracle weblogic server 9.0 -
oracle weblogic server 9.0 -
oracle weblogic server 9.0 maintenance_pack3
oracle weblogic server 9.0 maintenance_pack3
oracle weblogic server 9.0 maintenance_pack3
oracle weblogic server 9.1 -
oracle weblogic server 9.1 -
oracle weblogic server 9.1 -
oracle weblogic server 9.1 maintenance_pack3
oracle weblogic server 9.1 maintenance_pack3
oracle weblogic server 9.1 maintenance_pack3
oracle weblogic server 9.2 -
oracle weblogic server 9.2 -
oracle weblogic server 9.2 -
oracle weblogic server 9.2 maintenance_pack1
oracle weblogic server 9.2 maintenance_pack1
oracle weblogic server 9.2 maintenance_pack1
oracle weblogic server 9.2 maintenance_pack2
oracle weblogic server 9.2 maintenance_pack2
oracle weblogic server 9.2 maintenance_pack2
oracle weblogic server 9.2 maintenance_pack3
oracle weblogic server 9.2 maintenance_pack3
oracle weblogic server 9.2 maintenance_pack3
oracle weblogic server 10.0 -
oracle weblogic server 10.0 -
oracle weblogic server 10.0 -
oracle weblogic server 10.0 maintenance_pack1
oracle weblogic server 10.0 maintenance_pack1
oracle weblogic server 10.0 maintenance_pack1
oracle weblogic server 9.0
oracle weblogic server 9.1
oracle weblogic server 9.2.0.0.0