Vulnerability Name: | CVE-2008-4008 (CCN-44435) | ||||||||
Assigned: | 2008-10-14 | ||||||||
Published: | 2008-10-14 | ||||||||
Updated: | 2012-10-23 | ||||||||
Summary: | Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Note: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-4008 Source: IDEFENSE Type: UNKNOWN 20081029 Oracle WebLogic Apache Connector Source: CCN Type: SA32301 BEA WebLogic Server Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1021056 WebLogic Bugs Let Remote Users Execute Arbitary Code, Acces and Modify Information, and Deny Service Source: CCN Type: IBM Internet Security Systems Protection Advisory, October 14, 2008 Oracle WebLogic Server Apache Connector Remote Code Execution Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html Source: CCN Type: Oracle Critical Patch Update - October 2008 Oracle Critical Patch Update Advisory - October 2008 Source: SECTRACK Type: UNKNOWN 1021056 Source: VUPEN Type: UNKNOWN ADV-2008-2825 Source: XF Type: UNKNOWN application-server-stack-bo(44435) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 10.29.08 Oracle WebLogic Apache Connector Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2008-4008) Security vulnerability in WebLogic plug-in for Apache | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |