CVE-2006-1358: Medium severity Oracle Weblogic Portal vulnerability
Published Mar 22, 2006
·Updated
Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.
Affected Software
6 affected components
Oracle Weblogic Portal=8.1
Oracle Weblogic Portal=8.1-sp1
Oracle Weblogic Portal=8.1-sp2
Oracle Weblogic Portal=8.1-sp3
Oracle Weblogic Portal=8.1-sp4
Oracle Weblogic Portal=8.1-sp5
Remediation
Patch Available
Patch Available
Event History
Mar 22, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1358?
CVE-2006-1358 is considered a moderate severity vulnerability due to the potential for unauthorized access to user sessions.
2
How do I fix CVE-2006-1358?
To fix CVE-2006-1358, upgrade your BEA WebLogic Portal to a version that includes the necessary security patches.
3
What types of systems are affected by CVE-2006-1358?
CVE-2006-1358 affects BEA WebLogic Portal version 8.1 and its service packs up to SP5.
4
What impact does CVE-2006-1358 have on user privacy?
CVE-2006-1358 may expose one user's portlet data to another user, potentially breaching user privacy.
5
When was CVE-2006-1358 discovered?
CVE-2006-1358 was disclosed in March 2006.