Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-5457

9 documents5 sources
Severity
10.0CRITICAL
EPSS
81.8%
top 0.80%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 14
Latest updateMay 17

Description

Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDoracle/bea_product_suite7 versions+6

🔴Vulnerability Details

2
GHSA
GHSA-g2rx-86cx-wmmj: Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 102022-05-17
CVEList
CVE-2008-5457: Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 102009-01-14

💥Exploits & PoCs

2
Exploit-DB
BEA WebLogic - JSESSIONID Cookie Value Overflow (Metasploit)2010-07-03
Exploit-DB
Oracle WebLogic IIS connector JSESSIONID - Remote Overflow2009-04-01

🕵️Threat Intelligence

4
Talos
Rule release for today - April 21st 20092009-04-21
Talos
Rule release for today - April 21st 20092009-04-21
Talos
Rule release for today - January 27th 20092009-01-27
Talos
Rule release for today - January 27th 20092009-01-27
CVE-2008-5457 (CRITICAL CVSS 10) | Unspecified vulnerability in the Or | cvebase.io