Check Point Reference: | CPAI-2009-081 |
Date Published: | 8 May 2009 |
Severity: | High |
Last Updated: | Thursday 01 January, 2009 |
Source: | Secunia Advisory: SA34074 |
Industry Reference: | CVE-2009-1016 |
Protection Provided by: | |
Who is Vulnerable? | Oracle BEA WebLogic Server 7.0.x through 7.0 SP7 |
Vulnerability Description | A buffer overflow vulnerability was reported in BEA WebLogic Server, an Application Server platform for large enterprise web applications. The vulnerability is due to a boundary error while parsing SSL certificates. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted certificate to the target host. |
Vulnerability Details | The vulnerability exists in BEA WebLogic Server's connector software for Apache HTTP server. The connector software refers to the component shipped with WebLogic and used for communicating with the back-end application server. The vulnerability is due to improper validation of client certificates. |