← Vulnerability feed

Vulnerability record · CVE-2008-5457 · published 14 January 2009

CVE-2008-5457: Oracle BEA WebLogic Server Plugins unspecified remote vulnerability

Oracle · Bea Product Suite

An unspecified vulnerability exists in the Oracle BEA WebLogic Server Plugins component for Apache, Sun and IIS web servers within BEA Product Suite versions 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6 and 7.0 SP7. The record gives no root cause, affected function or attack vector detail, only that remote attackers can impact confidentiality, integrity and availability. Because the flaw is unauthenticated and network reachable with a maximum CVSS 2.0 score, it warrants prompt attention despite the thin description.

10.0 CVSS 2.0 High EPSS 61% · top 0.9%
10.0CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, combined with a 99.1st percentile EPSS score, makes this a top remediation priority despite the vague description.

What it is

An unspecified vulnerability exists in the Oracle BEA WebLogic Server Plugins component for Apache, Sun and IIS web servers within BEA Product Suite versions 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6 and 7.0 SP7. The record gives no root cause, affected function or attack vector detail, only that remote attackers can impact confidentiality, integrity and availability. Because the flaw is unauthenticated and network reachable with a maximum CVSS 2.0 score, it warrants prompt attention despite the thin description.

Impact

A remote attacker can fully compromise confidentiality, integrity and availability of the affected WebLogic Server Plugins deployment. The exact data or service affected is not specified in the record.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. It is exposed through the WebLogic Server Plugins for Apache, Sun and IIS web servers.

Exploitation

CISA KEV does not list this CVE and no reference carries an exploit tag, so public exploitation is not confirmed by the record. EPSS is high at 0.61309 (99.1st percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Apply the Oracle Critical Patch Update from January 2009 referenced in the advisory, or a later CPU, to all affected BEA Product Suite versions.
  • If patching cannot be done immediately, restrict network access to the WebLogic Server Plugins endpoints to trusted sources only.
  • Disable or remove unused WebLogic Server Plugins for Apache, Sun and IIS web servers where they are not required.
  • Monitor Oracle and vendor advisories for updated guidance, since the record does not describe the specific flaw or workaround.

Detection

  • Review web server and WebLogic logs for anomalous requests to plugin-handled paths from unexpected source IPs.
  • Alert on unexpected process, file or configuration changes on hosts running the affected WebLogic Server Plugins.
  • Correlate network traffic to plugin endpoints with authentication failures, crashes or unusual response sizes.
  • Inventory all hosts running BEA Product Suite versions listed in the advisory to confirm exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5457 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0079Oracle bea product suite vulnerabilityMultiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confide…EPSS 3.1%10.0CVE-2009-3403Oracle bea product suite vulnerabilityUnspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect conf…EPSS 3.1%10.0CVE-2009-1012Oracle bea product suite vulnerabilityUnspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.…EPSS 3.9%10.0CVE-2008-4008WebLogic Apache Connector stack buffer overflow in BEA Product SuiteAn unspecified vulnerability in the WebLogic Server Plugins for Apache component of BEA Product Suite (versions 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.…EPSS 56%analysed8.5CVE-2009-1016Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote…EPSS 2.0%6.8CVE-2009-1974Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote…EPSS 1.5%6.8CVE-2009-1975Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, an…EPSS 2.7%6.8CVE-2008-5461Oracle bea product suite information exposure vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remot…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2008-5457), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.