BEA Weblogic May Run Arbitrary Code
Several unchecked buffers exist in the product that could allow arbitrary code to execute on the server.
ITPro Today Staff
August 14, 2000
1 Min Read
Reported August 14, 2000 by CORE SDI
VERSIONS EFFECTED
BEA Systems Weblogic 5.x
DESCRIPTION
An unchecked buffers exist within Weblogic logic plug-in that can allow arbitrary code to execute on the server in the same security context that Weblogic proxy server runs under.
VENDOR RESPONSE
BEA Systems has released a bulletin and patches to correct the matter.
CREDIT
Discovered by CORE SDI
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like