CVE-2008-0903: Medium severity bea weblogic express vulnerability
Published Feb 22, 2008
·Updated
Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL.
Affected Software
2 affected components
Bea Systems Weblogic Express<=10.0
Bea Systems Weblogic Server<=10.0
Remediation
Patch Available
Event History
Feb 22, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0903?
CVE-2008-0903 is classified as a denial of service vulnerability.
2
How do I fix CVE-2008-0903?
To fix CVE-2008-0903, apply the relevant patches or updates released by Oracle for BEA WebLogic Server and WebLogic Express.
3
What versions are affected by CVE-2008-0903?
CVE-2008-0903 affects BEA WebLogic Server and WebLogic Express versions before 9.2 MP3 and 10.0 MP2.
4
Who can exploit CVE-2008-0903?
CVE-2008-0903 can be exploited by remote attackers who can send specially crafted URLs.
5
What is the impact of CVE-2008-0903?
The impact of CVE-2008-0903 is a potential web server crash, leading to a denial of service.