vendor:
WebLogic
by:
pusscat
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WebLogic
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2008-5457
CPE: a:bea:weblogic
Platforms Tested: Windows
2008
BEA WebLogic JSESSIONID Cookie Value Overflow
This module exploits a buffer overflow in BEA's WebLogic plugin. The vulnerable code is only accessible when clustering is configured. A request containing a long JSESSION cookie value can lead to arbitrary code execution.
Mitigation:
Apply the appropriate patch or upgrade to a non-vulnerable version of the software.