The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Oracle WebLogic Servers Vulnerable To Attacks


Posted by George Hulme, Jul 29, 2008 06:40 PM

When it comes to security vulnerabilities, this flaw is as ugly as it gets -- but, in this case, it's not all because of anything Oracle did wrong.


Thanks to the fact that a remotely exploitable vulnerability was disclosed on a mailing list just after Oracle's July 15 patch cycle, users of WebLogic Server and WebLogic Express are at an extraordinary level of risk to attack right now. The flaw in question, which Oracle has published this security bulletin about, enables an attacker to remotely compromise at-risk systems without any authentication. Nasty.

In this case, the security researcher that discovered the flaw chose to announce their find, along with accompanying attack code, without ever giving the database maker a chance to remedy the problem.

Here's what Eric Maurice had to say on Oracle's Global Product Security Blog:

Unfortunately, the person(s) who published this vulnerability and associated exploit codes didn't contact Oracle before publicly disclosing this issue. This means that the vulnerability was made public before providing Oracle an opportunity to develop an appropriate fix for this issue and notify its customers. In addition, the vulnerability was made public shortly after the publication of the July 15 Critical Patch Update, therefore prompting Oracle to issue an out of cycle security update.

So there you have it. Someone decided to not only dump a highly critical, remotely exploitable vulnerability on the world (and the software necessary to exploit the flaw), it also seems as if (I've no way of knowing for sure) that they cherry-picked the timing to fall right after Oracle's scheduled patch release.

That's just reckless.

Oracle has published work-around instructions here.

« Is eBay Getting Into Cloud Computing? | Main | Google Should Take Privacy Lessons From Cuil »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Visual Basic 10 Beta 2 Also Supports Task-Based Programming
  2. Here's to the First Responders!
  3. HPC Joins the Dummy Revolution?


Join The InformationWeek Group On LinkedIn


                           


  1. Susan Boyle Beats Michael Jackson On YouTube In '09
  2. Fake Steve Jobs' 'Operation Chokehold' To Strangle AT&T?
  3. Microsoft Offers Bing iPhone App
  4. Android Round-Up: 20k Apps, Facebook Update, OS2.1 Ported
  5. Verizon Wi-Fi Program Bypasses Smartphone Users


  1. Plurk Might Sue Microsoft For Code Theft
  2. Facebook Hit With FTC Complaint
  3. Massive Outage Hits BlackBerry Service
  4. NASA Launches Portable Cloud Effort
  5. Government Grapples With EMR Security, Privacy
  6. IBM Rational Tools Aid Smart Device Makers

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007