Denial of Service in BEA Weblogic Server
A Denial of Service (DoS) condition exists in BEA Weblogic Server 6.1.
January 9, 2002
Reported January 8, 2002, byPeter Gründl.
VERSIONS AFFECTED
BEA Weblogic Server 6.1 for Windows 2000
BEA Weblogic Server 6.1 for Windows NT
DESCRIPTION
ADenial of Service (DoS) condition exists in BEA Weblogic Server 6.1. Byappending a DOS device request to a .jsp file request, such as “aux.jsp,” anattacker can invoke an external compiler with a working thread that neverfinishes. When the intruder uses 10 or more working threads in this manner, theserver will no longer process any more requests, even if the requests arelegitimate.
VENDOR RESPONSE
Thevendor, BEA, has released ServicePack 2 to correct this concern.
CREDIT
Discovered by PeterGründl.
About the Author
You May Also Like