Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-1016
StatusUNKNOWN
DescriptionUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate.
SeverityHigh
CVSS score8,5
CVSS vector(AV:N/AC:M/Au:S/C:C/I:C/A:C)
PhaseASSIGNED (04.02.2011)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1016
ReferencesBID : 34461
 CERT : TA09-105A
 CONFIRM : http://www.oracle.com/technology/deploy/security/c...
 MISC : http://secunia.com/secunia_research/2009-23/
 SECTRACK : 1022059
 XF : oracle-bea-ssl-bo(64934)
SecurityVulns:Oracle multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server