CVE-2008-5457 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 61.3% (pctl 99)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 61.31% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-01-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| oracle | bea product suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BEA WebLogic - JSESSIONID Cookie Value Overflow (Metasploit) | 2010-07-03 |
| exploit-db | Oracle WebLogic IIS connector JSESSIONID - Remote Overflow | 2009-04-01 |
References
- http://secunia.com/advisories/33526
- http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html
- http://www.securityfocus.com/bid/33177
- http://www.securitytracker.com/id?1021571
- http://www.vupen.com/english/advisories/2009/0115
- http://secunia.com/advisories/33526
- http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html
- http://www.securityfocus.com/bid/33177
- http://www.securitytracker.com/id?1021571
- http://www.vupen.com/english/advisories/2009/0115
→ the Explorer · watch your stack · NVD