WebLogic and Tuxedo products contain a flaw that may lead to an unauthorized access, in the form of impersonation, and information disclosure. The issue exists due to improper handling of SSL certificates, which may allow a user to impersonate web sites and digitally signed content, resulting in a loss of confidentiality.
Classification
Location:
Remote/Network Access Required
Attack Type:
Hijacking
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Solution
Upgrade to listed versions or higher, as it has been reported to fix this vulnerability. Upgrades and/or patches are required as there are no known workarounds.
WebLogic Server and Express 7.0 or 7.0.0.1: - Apply Service Pack 2 - If using NSAPI Plugin, ISAPI Plugin, or Apache Plugin should upgrade to the 7.0 Service Pack 2 version of the Plugin
WebLogic Server and Express 6.1: - Apply Service Pack 5 - If using NSAPI Plugin, ISAPI Plugin, or Apache Plugin should upgrade to the 6.1 Service Pack 5 version of the Plugin.
WebLogic Server and Express 5.1: - Apply Service Pack 13 - Apply CR090101_src510 patch.
WebLogic Enterprise 5.1: - Apply Rolling Patch 145 or later
WebLogic Enterprise 5.0: - Apply Rolling Patch 59 or later
WebLogic Tuxedo 8.1: - Apply Rolling Patch 12 or later
WebLogic Tuxedo 8.0: - Apply Rolling Patch 166 or later