CVE-2010-0068
published 2010-01-13CVE-2010-0068: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.08%
79.4th percentile
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| oracle | bea_product_suite | — | — |
| oracle | bea_product_suite | — | — |
| oracle | bea_product_suite | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2fq3-p8p7-3cvw: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9
ghsa_unreviewed·2022-05-02
CVE-2010-0068 [MEDIUM] GHSA-2fq3-p8p7-3cvw: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.
Red Hat
kernel: x86/bugs: Use code segment selector for VERW operand
vendor_redhat·2024-10-29·CVSS 5.5
CVE-2024-50072 [MEDIUM] CWE-20 kernel: x86/bugs: Use code segment selector for VERW operand
kernel: x86/bugs: Use code segment selector for VERW operand
In the Linux kernel, the following vulnerability has been resolved:
x86/bugs: Use code segment selector for VERW operand
Robert Gill reported below #GP in 32-bit mode when dosemu software was
executing vm86() system call:
general protection fault: 0000 [#1] PREEMPT SMP
CPU: 4 PID: 4610 Comm: dosemu.bin Not tainted 6.6.21-gentoo-x86 #1
Hardware name: Dell Inc. PowerEdge 1950/0H723K, BIOS 2.7.0 10/30/2010
EIP: restore_all_switch_stack+0xbe/0xcf
EAX: 00000000 EBX: 00000000 ECX: 00000000 EDX: 00000000
ESI: 00000000 EDI: 00000000 EBP: 00000000 ESP: ff8affdc
DS: 0000 ES: 0000 FS: 0000 GS: 0033 SS: 0068 EFLAGS: 00010046
CR0: 80050033 CR2: 00c2101c CR3: 04b6d000 CR4: 000406d0
Call Trace:
show_regs+0x70/0x78
die_addr+0x29/0x70
exc_genera
Suricata
ET WEB_SERVER HP OpenView Network Node Manager CGI Directory Traversal
suricata·2010-07-30·CVSS 5.0
CVE-2008-0068 [MEDIUM] ET WEB_SERVER HP OpenView Network Node Manager CGI Directory Traversal
ET WEB_SERVER HP OpenView Network Node Manager CGI Directory Traversal
Rule: alert http1 $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER HP OpenView Network Node Manager CGI Directory Traversal"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/OvCgi/"; nocase; content:"/OpenView5.exe?"; nocase; distance:0; fast_pattern; content:"Action=../../"; nocase; distance:0; http.protocol; content:"HTTP/1."; reference:bugtraq,28745; reference:cve,CVE-2008-0068; reference:url,aluigi.altervista.org/adv/closedviewx-adv.txt; classtype:web-application-attack; sid:2008171; rev:15; metadata:created_at 2010_07_30, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discov
No public exploits indexed.
No writeups or analysis indexed.
2010-01-13
Published