First published: Tue Jul 14 2009(Updated: )
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle BEA Product Suite | =9.1 | |
Oracle BEA Product Suite | =8.1-sp6 | |
Oracle BEA Product Suite | =10.0-mp1 | |
Oracle BEA Product Suite | =7.0-sp7 | |
Oracle BEA Product Suite | =9.0 | |
Oracle BEA Product Suite | =10.3 | |
Oracle BEA Product Suite | =9.2-mp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1974 is considered to have a high severity due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2009-1974, it is recommended to apply the latest patches provided by Oracle for affected versions of the BEA Product Suite.
CVE-2009-1974 affects Oracle BEA Product Suite versions 7.0 SP7 through 10.3, including multiple sub-releases.
Yes, CVE-2009-1974 can be exploited by remote attackers, posing a significant risk to services utilizing affected versions.
Exploitation of CVE-2009-1974 can lead to unauthorized access, data breaches, and potential disruption of service.