CVE-2007-0415: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0415?
CVE-2007-0415 has a high severity level due to the ability of attackers to bypass access control restrictions.
How do I fix CVE-2007-0415?
To mitigate CVE-2007-0415, upgrade BEA WebLogic Server to a version later than 8.1 SP5.
What versions of WebLogic Server are affected by CVE-2007-0415?
CVE-2007-0415 affects BEA WebLogic Server versions from 8.1 up to and including 8.1 SP5.
What type of access control issue is present in CVE-2007-0415?
CVE-2007-0415 involves improper enforcement of access control after dynamic updates and redeployments.
How can attackers exploit CVE-2007-0415?
Attackers can exploit CVE-2007-0415 by bypassing intended access restrictions through dynamic application redeployments.