First published: Fri Feb 22 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =6.1-sp7 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp5 | |
Oracle WebLogic Server | =7.0-sp6 | |
Oracle WebLogic Server | =7.0-sp7 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp3 | |
Oracle WebLogic Server | =8.1-sp4 | |
Oracle WebLogic Server | =8.1-sp5 | |
Oracle WebLogic Server | =8.1-sp6 | |
Oracle WebLogic Server | =9.0-ga | |
Oracle WebLogic Server | =9.1-ga | |
Oracle WebLogic Server | =10.0 | |
Oracle WebLogic Server | =10.0_mp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0902 is considered to have a moderate severity due to its potential for cross-site scripting attacks.
To fix CVE-2008-0902, ensure that you apply the latest patches provided by Oracle for affected versions of WebLogic Server.
CVE-2008-0902 affects Oracle WebLogic Server versions 6.1 through 10.0 MP1.
Yes, CVE-2008-0902 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
CVE-2008-0902 describes multiple cross-site scripting (XSS) vulnerabilities that can lead to unauthorized actions performed on behalf of users.