Oracle WebLogic Server Plug-in Remote Overflow (1166189)

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote web server uses a module that is affected by a buffer
overflow vulnerability.

Description :

The remote web server is using the WebLogic plug-in for Apache, IIS,
or Sun web servers, a module included with Oracle (formerly BEA)
WebLogic Server and used to proxy requests from an HTTP server to
WebLogic.

The version of this plug-in on the remote host is affected by an
as-yet unspecified buffer overflow that is triggered when processing a
specially crafted request. An unauthenticated, remote attacker can
leverage this issue to execute arbitrary code on the remote host.

Note that Nessus has not tried to exploit this issue but rather has
only checked the affected plug-in's change number / build timestamp.

See also :

http://www.nessus.org/u?5c4d9050
http://www.securitytracker.com/id?1021571

Solution :

Install the latest web server plug-in as described in the vendor
advisory above.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 35374 ()

Bugtraq ID: 33177

CVE ID: CVE-2008-5457