Vulnerability Name: | CVE-2008-5457 (CCN-48001) | ||||||||
Assigned: | 2008-12-11 | ||||||||
Published: | 2009-01-13 | ||||||||
Updated: | 2012-10-23 | ||||||||
Summary: | Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5457 Source: CCN Type: SA33526 Oracle BEA WebLogic Server Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 33526 Source: CCN Type: SECTRACK ID: 1021571 WebLogic Bugs Let Remote Users Execute Arbitary Code, Acces and Modify Information, and Deny Service Source: CCN Type: Oracle Critical Patch Update Advisory - January 2009 Oracle Critical Patch Update Advisory - January 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html Source: CCN Type: OSVDB ID: 51311 Oracle BEA WebLogic Plug-in For Multiple Web Servers HTTP Request Remote Overflow DoS Source: BID Type: UNKNOWN 33177 Source: CCN Type: BID-33177 Oracle January 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1021571 Source: VUPEN Type: UNKNOWN ADV-2009-0115 Source: XF Type: UNKNOWN oracle-weblogic-plugins-code-execution(48001) Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2008-5457) Security vulnerability in WebLogic plug-ins for Apache, Sun and IIS Web servers | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |