December 21, 2000

BEA WebLogic Server vulnerability

Author: JT Smith

From SecurityFocus: "Unchecked buffers exist in a particular handler for URL requests that
begin with two dots "..". Depending on the data entered into the buffer,
WebLogic Server could be forced to crash or arbitrary code could be
executed on the system in the security context of the web server. In
the event that random data was sent in order to crash the server,
restarting the application would be required in order to regain normal
functionality."

Category:

  • Linux
Click Here!