First published: Tue Jan 23 2007(Updated: )
BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | <=8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =9.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =9.1 | |
Oracle WebLogic Server | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0418 has a high severity rating due to its potential for unauthorized remote access to EJB methods.
To fix CVE-2007-0418, update your BEA WebLogic Server to a patched version that enforces a security policy for EJB methods.
CVE-2007-0418 affects WebLogic Server versions 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1.
Exploitation of CVE-2007-0418 allows remote attackers to gain unauthorized access to EJB methods with array parameters.
A temporary workaround for CVE-2007-0418 may involve restricting access to affected EJB methods until an update can be applied.