BEA Weblogic May Run Arbitrary Code

Several unchecked buffers exist in the product that could allow arbitrary code to execute on the server.

ITPro Today Staff

August 14, 2000

1 Min Read
ITPro Today logo

 

Reported August 14, 2000 by CORE SDI

VERSIONS EFFECTED

  • BEA Systems Weblogic 5.x

DESCRIPTION

An unchecked buffers exist within Weblogic logic plug-in that can allow arbitrary code to execute on the server in the same security context that Weblogic proxy server runs under.

VENDOR RESPONSE

BEA Systems has released a bulletin and patches to correct the matter.

CREDIT
Discovered by CORE SDI

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like