CVE-2008-5457
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 61%
from disclosure to weapon77 days
Published on NVDJan 14
1st PoC+77d
metasploitJan 13
exploitation probability
61%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16762unverifiedexploitdbwww.exploit-db.com/exploits/8336unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.