HTTP: BEA Weblogic Encoding Value Overflow

This signature detects attempts to exploit a known vulnerability in BEA Weblogic. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Oracle has released the October 2008 critical patch update addressing 36 vulnerabilities affecting the following software: Oracle Database Oracle Application Server Oracle E-Business Suite Oracle PeopleSoft Enterprise PeopleTools Oracle PeopleSoft Enterprise Oracle JD Edwards EnterpriseOne Tools Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle Workshop for WebLogic (formerly BEA WebLogic Workshop)

Affected Products

Bea_systems weblogic_server

Short Name
HTTP:WEBLOGIC:ENCODING
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
BEA CVE-2008-4008 Encoding Overflow Value Weblogic bid:31683
Release Date
09/15/2009
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3730
False Positive
Unknown
Vendors

Oracle

Bea_systems

CVSS Score

10.0

Found a potential security threat?