Mailing List

Name:

Email:

[SingCERT] Oracle WebLogic Server Remote Security Vulnerability

Attention: open in a new window. PDFPrintE-mail

[ Summary ]

Oracle WebLogic Server is prone to a remote vulnerability in Node Manager.

The vulnerability can be exploited over the TCP/IP protocol. The Node Manager sub component is affected.

Fixes are available.

[ Affected Systems ]

Oracle Weblogic Server 10.0 MP2 cpe:/a:oracle:weblogic_server:10.0:mp2 SYMC

Oracle Weblogic Server 10.3.2 cpe:/a:oracle:weblogic_server:10.3.2 NVD

Oracle Weblogic Server 10.3.3 cpe:/a:oracle:weblogic_server:10.3.3 NVD

Oracle Weblogic Server 9.0 GA cpe:/a:oracle:weblogic_server:9.0:ga SYMC

Oracle Weblogic Server 9.1 cpe:/a:oracle:weblogic_server:9.1 SYMC

Oracle Weblogic Server 9.2 cpe:/a:oracle:weblogic_server:9.2 SYMC

Oracle Weblogic Server 9.3 MP3 cpe:/a:oracle:weblogic_server:9.3:mp3 SYMC

[ Impact Analysis ]

Currently there are not enough technical details to depict the effect.

[ Solution/Workaround ]

Vendor updates are available. Please contact the vendor for more informations.

[ Reference ]

  • http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html