Oracle WebLogic Server 10.3

CPE Details

Oracle WebLogic Server 10.3
10.3
2008-09-05
18h08 +00:00
2018-01-10
18h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:oracle:weblogic_server:10.3:*:*:*:*:*:*:*

Informations

Vendor

oracle

Product

weblogic_server

Version

10.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-3213 2018-10-16 23h00 +00:00 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Docker Images). The supported version that is affected is prior to Docker 12.2.1.3.20180913. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
7.5
High
CVE-2008-3257 2008-07-22 14h00 +00:00 Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
10