Denial of Service in BEA Weblogic Server

A Denial of Service (DoS) condition exists in BEA Weblogic Server 6.1.

Ken Pfeil

January 9, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 8, 2002, byPeter Gründl.

VERSIONS AFFECTED

  • BEA Weblogic Server 6.1 for Windows 2000

  • BEA Weblogic Server 6.1 for Windows NT

 

DESCRIPTION

ADenial of Service (DoS) condition exists in BEA Weblogic Server 6.1. Byappending a DOS device request to a .jsp file request, such as “aux.jsp,” anattacker can invoke an external compiler with a working thread that neverfinishes. When the intruder uses 10 or more working threads in this manner, theserver will no longer process any more requests, even if the requests arelegitimate.

 


VENDOR RESPONSE

 

Thevendor, BEA, has released ServicePack 2 to correct this concern.

 

CREDIT
Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like