Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
Conclusion & alert: CVE-2008-3257 is rated High Exploit Risk (89.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 80.78%, 99th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 18897 | exploit_db | edb | 2012-05-19 | Exploit-DB ↗ |
| 6089 | exploit_db | edb | 2008-07-17 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-02 | 81.33% | 80.78% | -0.55% |
| 2 | 2025-10-11 | 78.22% | 81.33% | +3.10% |
| 3 | 2025-03-25 | — | 78.22% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
Oracle has released a workaround for CVE-2008-3257. Information is available at: http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| bea | weblogic_server | 3.1.8 | cpe:2.3:a:bea:weblogic_server:3.1.8:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.0 | cpe:2.3:a:bea:weblogic_server:4.0:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.0.4 | cpe:2.3:a:bea:weblogic_server:4.0.4:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.5 | cpe:2.3:a:bea:weblogic_server:4.5:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.5.1 | cpe:2.3:a:bea:weblogic_server:4.5.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.5.1 | cpe:2.3:a:bea:weblogic_server:4.5.1:sp15:*:*:*:*:*:* |
| bea | weblogic_server | 4.5.2 | cpe:2.3:a:bea:weblogic_server:4.5.2:*:*:*:*:*:*:* |
| bea | weblogic_server | 4.5.2 | cpe:2.3:a:bea:weblogic_server:4.5.2:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 4.5.2 | cpe:2.3:a:bea:weblogic_server:4.5.2:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp10:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp11:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp12:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp13:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp5:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp6:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp7:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp8:*:*:*:*:*:* |
| bea | weblogic_server | 5.1 | cpe:2.3:a:bea:weblogic_server:5.1:sp9:*:*:*:*:*:* |
| bea | weblogic_server | 6.0 | cpe:2.3:a:bea:weblogic_server:6.0:*:*:*:*:*:*:* |
| bea | weblogic_server | 6.0 | cpe:2.3:a:bea:weblogic_server:6.0:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 6.0 | cpe:2.3:a:bea:weblogic_server:6.0:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 6.0 | cpe:2.3:a:bea:weblogic_server:6.0:sp6:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:* |
| bea | weblogic_server | 6.1 | cpe:2.3:a:bea:weblogic_server:6.1:sp8:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:* |
| bea | weblogic_server | 7.0 | cpe:2.3:a:bea:weblogic_server:7.0:sp7:*:*:*:*:*:* |
| bea | weblogic_server | 7.0.0.1 | cpe:2.3:a:bea:weblogic_server:7.0.0.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 7.0.0.1 | cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 7.0.0.1 | cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 7.0.0.1 | cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 7.0.0.1 | cpe:2.3:a:bea:weblogic_server:7.0.0.1:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:* |
| bea | weblogic_server | 8.1 | cpe:2.3:a:bea:weblogic_server:8.1:sp6:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:ga:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:sp1:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:sp2:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:sp3:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:sp4:*:*:*:*:*:* |
| bea | weblogic_server | 9.0 | cpe:2.3:a:bea:weblogic_server:9.0:sp5:*:*:*:*:*:* |
| bea | weblogic_server | 9.1 | cpe:2.3:a:bea:weblogic_server:9.1:*:*:*:*:*:*:* |
| bea | weblogic_server | 9.1 | cpe:2.3:a:bea:weblogic_server:9.1:ga:*:*:*:*:*:* |
| bea | weblogic_server | 9.2 | cpe:2.3:a:bea:weblogic_server:9.2:*:*:*:*:*:*:* |
| bea | weblogic_server | 9.2 | cpe:2.3:a:bea:weblogic_server:9.2:mp1:*:*:*:*:*:* |
| bea | weblogic_server | 9.2 | cpe:2.3:a:bea:weblogic_server:9.2:mp2:*:*:*:*:*:* |
| bea | weblogic_server | 10.0 | cpe:2.3:a:bea:weblogic_server:10.0:*:*:*:*:*:*:* |
| bea_systems | apache_connector_in_weblogic_server | — | cpe:2.3:a:bea_systems:apache_connector_in_weblogic_server:*:*:*:*:*:*:*:* |
| bea_systems | weblogic_server | 10.0_mp1 | cpe:2.3:a:bea_systems:weblogic_server:10.0_mp1:*:*:*:*:*:*:* |
| oracle | weblogic_server | <= 10.3 | cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* |