10

CVE-2008-4008

Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.

Data is provided by the National Vulnerability Database (NVD)
OracleBea Product Suite Version6.1 Updatesp7
OracleBea Product Suite Version7.0 Updatesp7
OracleBea Product Suite Version8.1 Updatesp6
OracleBea Product Suite Version9.0
OracleBea Product Suite Version9.1
OracleBea Product Suite Version9.2 Updatemp3
OracleBea Product Suite Version10.0 Updatemp1
OracleBea Product Suite Version10.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 85.81% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C