Vulnerability Name: | CVE-2009-1012 (CCN-50050) | ||||||||
Assigned: | 2009-04-14 | ||||||||
Published: | 2009-04-14 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. Note: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1012 Source: OSVDB Type: UNKNOWN 53765 Source: MISC Type: UNKNOWN http://secunia.com/secunia_research/2009-22/ Source: CCN Type: SECTRACK ID: 1022059 Oracle WebLogic Server and Portal Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions Source: CCN Type: Oracle Critical Patch Update Advisory - April 2009 Oracle Critical Patch Update Advisory - April 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2009-1012) Security vulnerability in WebLogic plug-ins for Apache and IIS Web servers Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technology/deploy/security/wls-security/1012.html Source: CCN Type: OSVDB ID: 53765 Oracle BEA WebLogic Server Plug-ins for Web Servers Unspecified Remote Overflow Source: BID Type: UNKNOWN 34461 Source: CCN Type: BID-34461 Oracle April 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1022059 Source: CERT Type: US Government Resource TA09-105A Source: XF Type: UNKNOWN oracle-weblogic-plugins-system-integrity2(50050) Source: XF Type: UNKNOWN oracle-bea-http-bo(64935) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |