CVE-2008-0900
22.02.2008, 21:44
Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bea | weblogic_server | 8.1:sp4 |
| bea | weblogic_server | 8.1:sp4 |
| bea | weblogic_server | 8.1:sp5 |
| bea | weblogic_server | 8.1:sp5 |
| bea | weblogic_server | 8.1:sp6 |
| bea | weblogic_server | 8.1:sp6 |
| bea | weblogic_server | 9.2 |
| bea | weblogic_server | 9.2:mp1 |
| bea | weblogic_server | 10.0 |
| bea_systems | weblogic_express | 9.2:mp1 |
| bea_systems | weblogic_express | 10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References