First published: Thu May 20 2004(Updated: )
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0470 has a moderate severity level as it can lead to improper access control due to the removal of security-role-assignment tags.
CVE-2004-0470 affects BEA WebLogic Server versions 7.0 through SP5 and 8.1 through SP2.
To fix CVE-2004-0470, you should apply the latest service pack or patch provided by Oracle for the affected versions.
The risks associated with CVE-2004-0470 include unauthorized access and manipulation of security roles due to the potential removal of necessary security configurations.
Not addressing CVE-2004-0470 could result in significant security vulnerabilities, allowing attackers to bypass security roles and gain unauthorized access to applications.