CVE-2008-0902: XSS
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0902?
CVE-2008-0902 is considered to have a moderate severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-0902?
To fix CVE-2008-0902, ensure that you apply the latest patches provided by Oracle for affected versions of WebLogic Server.
Which versions of Oracle WebLogic Server are affected by CVE-2008-0902?
CVE-2008-0902 affects Oracle WebLogic Server versions 6.1 through 10.0 MP1.
Can CVE-2008-0902 be exploited remotely?
Yes, CVE-2008-0902 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What is the nature of the vulnerability described in CVE-2008-0902?
CVE-2008-0902 describes multiple cross-site scripting (XSS) vulnerabilities that can lead to unauthorized actions performed on behalf of users.