SSL: Oracle BEA WebLogic Server Plug-ins Certificate Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the BEA WebLogic Server Plugins. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the affected application.

Extended Description

Oracle has released the April 2009 critical patch update that addresses 43 vulnerabilities affecting the following software: Oracle Database Oracle Audit Vault Oracle Application Server Oracle Outside In SDK HTML Export Oracle XML Publisher Oracle BI Publisher Oracle E-Business Suite PeopleSoft Enterprise PeopleTools PeopleSoft Enterprise HRMS Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle Data Service Integrator Oracle AquaLogic Data Services Platform Oracle JRockit

Affected Products

Bea_systems weblogic_server

References

BugTraq: 34461

CVE: CVE-2009-1016

Short Name
SSL:OVERFLOW:BEA-PLUGINS-CERT
Severity
Major
Recommended
False
Recommended Action
None
Category
SSL
Keywords
BEA Buffer CVE-2009-0190 CVE-2009-1016 Certificate Oracle Overflow Plug-ins Server WebLogic bid:34461
Release Date
07/25/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Oracle

Bea_systems

CVSS Score

8.5

Found a potential security threat?