CVE-2007-0426: Medium severity Oracle Weblogic Portal vulnerability
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0426?
CVE-2007-0426 is considered a critical vulnerability that can lead to unauthorized access by allowing attackers to bypass entitlement policies.
How do I fix CVE-2007-0426?
To fix CVE-2007-0426, ensure that the Administrative Server is available when making entitlement policy changes and consider applying available patches from Oracle.
What software is affected by CVE-2007-0426?
CVE-2007-0426 affects BEA WebLogic Portal version 9.2 running in a clustered environment.
What is the risk associated with CVE-2007-0426?
The risk associated with CVE-2007-0426 is that unauthorized users may gain access to resources due to ineffective entitlement policy propagation.
When was CVE-2007-0426 reported?
CVE-2007-0426 was reported in the year 2007.