Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:WEBLOGIC-SERVER

Severity

High

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

Oracle WebLogic Server Session Fixation

Release Date

2011/07/12

Update Number

1954

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle WebLogic Server Session Fixation


This signature detects attempts to exploit a known vulnerability in Oracle WebLogic Server. A successful attack can result in unauthorized access to the affected product.

Extended Description

Oracle Weblogic is prone to a remote session fixation vulnerability. The vulnerability can be exploited over the 'HTTP' protocol. The 'Servlet Container' sub component is affected. Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the affected application. This vulnerability affects the following supported versions: 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, 10.3.3

Affected Products

  • Oracle Weblogic Server 10
  • Oracle Weblogic Server 10.0 MP1
  • Oracle Weblogic Server 10.0 MP2
  • Oracle Weblogic Server 10.1
  • Oracle Weblogic Server 10.3
  • Oracle Weblogic Server 10.3.1
  • Oracle Weblogic Server 10.3.2
  • Oracle Weblogic Server 10.3.3
  • Oracle Weblogic Server 9.0 GA
  • Oracle Weblogic Server 9.1
  • Oracle Weblogic Server 9.1 GA
  • Oracle Weblogic Server 9.2
  • Oracle Weblogic Server 9.2.4
  • Oracle Weblogic Server 9.2 MP1
  • Oracle Weblogic Server 9.2 MP2
  • Oracle Weblogic Server 9.2 MP3

References

  • BugTraq: 45852
  • CVE: CVE-2010-4437

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out