Vulnerable Systems:
* Oracle BEA Weblogic Server version 10.3
Vulnerabilities found in console-help.portal script of Weblogic Server. Linked XSS found in /consolehelp/console-help.portal. Vulnerable parameter "searchQuery"
Patch Availability:
Information was published in CPU July 2009. All customers can download CPU petches following instructions from:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html