CVE-2005-2680: Medium severity Oracle Weblogic Portal vulnerability
Published Aug 23, 2005
·Updated
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.
Affected Software
5 affected components
Oracle Weblogic Portal=8.1
Oracle Weblogic Portal=8.1-sp1
Oracle Weblogic Portal=8.1-sp2
Oracle Weblogic Portal=8.1-sp3
Oracle Weblogic Portal=8.1-sp4
Remediation
Patch Available
Event History
Aug 23, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2680?
CVE-2005-2680 is rated as a high severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2005-2680?
To fix CVE-2005-2680, upgrade to a newer version of BEA WebLogic Portal that addresses this vulnerability.
3
Who is affected by CVE-2005-2680?
CVE-2005-2680 affects users of BEA WebLogic Portal versions 8.1 through SP4.
4
What type of vulnerability is CVE-2005-2680?
CVE-2005-2680 is an access control vulnerability that allows unauthorized access to specific pages.
5
Can CVE-2005-2680 be exploited remotely?
Yes, CVE-2005-2680 can be exploited remotely by attackers through crafted URLs.