Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:WEBLOGIC:URL-REVEAL-SRC

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Weblogic Malformed URL Reveal JSP Source

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Weblogic Malformed URL Reveal JSP Source


This signature detects attempts to exploit a known vulnerability in Bea Weblogic. Version V6.1 Service Pack 2 on Windows 2000 Server is vulnerable. Attackers can append the string "%00x" to a URL request to read the contents of a .jsp file.

Extended Description

Many webservers are case-sensitive, but do not have all possible combinations of cases in mapped extensions mapped properly. By changing the letters in a JSP or a JHTML file extension from lower case to upper case (eg: .jsp or .jhtml becomes .JSP or .JHTML) in a URL the server does not recognize the file extension and sends the file normally. In that manner, a user is able to access the source code to those specific files.

Affected Products

  • BEA Systems Weblogic 3.1.8
  • BEA Systems Weblogic 4.0.4
  • BEA Systems Weblogic Server 3.1.8
  • BEA Systems Weblogic Server 4.5.1
  • IBM Websphere Application Server 3.0.2 .1
  • Unify eWave ServletExec 3.0.0

References

  • BugTraq: 1328
  • CVE: CVE-2000-0499
  • URL: http://www.securityfocus.com/bid/1328
  • URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2000-0499
  • URL: http://xforce.iss.net/static/4694.php

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out