CVE-2006-0428: High severity Oracle Weblogic Portal vulnerability
Published Jan 25, 2006
·Updated
Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.
Affected Software
3 affected components
Oracle Weblogic Portal=8.1-sp3
Oracle Weblogic Portal=8.1-sp4
Oracle Weblogic Portal=8.1-sp5
Remediation
Patch Available
Patch Available
Event History
Jan 25, 2006
CVE Published
11:07 PM
Jan 26, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0428?
CVE-2006-0428 is classified as a high severity vulnerability due to its ability to allow unauthorized access to restricted resources.
2
How do I fix CVE-2006-0428?
To fix CVE-2006-0428, upgrade BEA WebLogic Portal to a version that is not affected, such as the latest service pack.
3
What versions of BEA WebLogic Portal are affected by CVE-2006-0428?
CVE-2006-0428 affects BEA WebLogic Portal versions 8.1 SP3, SP4, and SP5.
4
Can CVE-2006-0428 be exploited remotely?
Yes, CVE-2006-0428 can be exploited remotely by attackers using crafted URLs.
5
What type of attacks are possible with CVE-2006-0428?
CVE-2006-0428 enables remote attackers to gain unauthorized access to restricted web resources.