Published:2012/01/20 Last Updated:2012/01/20
JVN#54779201
Oracle WebLogic Server vulnerable to cross-site scripting
Overview
Oracle WebLogic Server contains a cross-site scripting vulnerability.
Products Affected
- Oracle WebLogic Server 9.2.4, 10.0.2, 10.3.3, 10.3.4, 10.3.5
Description
Oracle WebLogic Server contains a cross-site scripting vulnerability on the management console.
Impact
An arbitrary script may be executed on the browser of the user who is logged into the administration console of Oracle WebLogic Server.
Solution
Update the Software
Apply the latest update according to the information provided by the developer.
Vendor Status
Vendor | Link |
Oracle | Oracle Critical Patch Update Advisory - January 2012 |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2011.01.20
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Minetoshi Takizawa reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2012-0077 |
JVN iPedia |
JVNDB-2012-000007 |