First published: Fri Aug 31 2007(Updated: )
BEA WebLogic Server 9.1 does not properly handle propagation of an admin server's security policy change log to temporarily unavailable managed servers, which might allow attackers to bypass intended restrictions, a different vulnerability than CVE-2007-0426.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4614 is classified as a potentially high-severity vulnerability due to its ability to allow attackers to bypass security restrictions.
To fix CVE-2007-4614, ensure that all managed servers are properly configured to propagate security policy changes from the admin server.
CVE-2007-4614 specifically affects BEA WebLogic Server version 9.1.
Yes, CVE-2007-4614 may allow unauthorized access by enabling attackers to bypass intended security restrictions.
Yes, CVE-2007-4614 is a different vulnerability than CVE-2007-0426, although both affect WebLogic Server.