The Channel logo

News

By | Dan Goodin 8th February 2010 22:38

Oracle issues emergency security patch for WebLogic

'Full disclosure' yields results

Oracle issued an emergency patch for its WebLogic Server almost two weeks after a white-hat hacker disclosed a vulnerability that allows criminals to remotely execute commands on the webserver with no authentication necessary.

The vulnerability in the Node Manager component of Oracle WebLogic Server can be exploited by carrying out commands over a network without requiring a username and password, Oracle warned late last week. The company went through the unusual step of issuing a patch outside its normal update cycle.

The out-of-band release came 12 days after Evgeny Legerov, CEO of Russian security firm Intevydis, disclosed a WebLogic vulnerability that sounded almost identical to the one described in the Oracle advisory. Legerov recently blogged his intention to do away with so-called "responsible disclosure" practices, in which researchers privately notify software makers about bugs in their products to prevent criminals from exploiting the defects before they're fixed.

Intevydis was dispensing with the practice "because it is enforced by vendors and it allows vendors to exploit security researches to do QA work for free," he wrote.

The vulnerability carries a Common Vulnerability Scoring System severity score of 10 on Windows versions 9.0 and later of WebLogic. Versions for non-Windows operating systems, by contrast, carry a rating 7.5.

Oracle's advisory strongly recommended users apply the emergency patch, along with a cumulative WebLogic patch issued in January.

"This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password," Oracle warned. "A knowledgeable and malicious remote user can exploit this vulnerability which can result in impacting the availability, integrity and confidentiality of the targeted system." ®

comment icon Read 1 comment on this article alert Send corrections

Opinion

closed_sign shut down under collapsed liquidation

Eddie Pacey

Does it do what it says on the tin? Credit insurance, that is
Funnel of cash. Credit: via SXC – http://www.sxc.hu/profile/Leonardini
management procure6

Dale Vile

Corporate decision-making's got nowt on non-techie MDs

Alexandre Mesguich

Cloud, virtualisation, mobile tech require fatter pipes

Features

Pigeon crapping on statue
Guess who just tried to break into the warehouse?
Vendors struggling to reinflate the bubble
Hellawell on being 'tight' - and his part in Thatcher's downfall
Square Group new premises