| Vulnerability Name: | CVE-2008-4013 (CCN-45912) | ||||||||
| Assigned: | 2008-10-14 | ||||||||
| Published: | 2008-10-14 | ||||||||
| Updated: | 2017-08-08 | ||||||||
| Summary: | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-4013 Source: CCN Type: SA32301 BEA WebLogic Server Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1021056 WebLogic Bugs Let Remote Users Execute Arbitary Code, Acces and Modify Information, and Deny Service Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html Source: CCN Type: Oracle Critical Patch Update - October 2008 Oracle Critical Patch Update Advisory - October 2008 Source: SECTRACK Type: UNKNOWN 1021056 Source: VUPEN Type: UNKNOWN ADV-2008-2825 Source: XF Type: UNKNOWN oracle-weblogic-webapps-unauth-access(45912) Source: XF Type: UNKNOWN oracle-weblogic-webapps-unauth-access(45912) Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2008-4013) Protected webapps may be displayed under certain conditions | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||