First published: Thu Feb 21 2008(Updated: )
Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bea Systems Weblogic Portal | =8.1_sp6 | |
Oracle Weblogic Portal | =8.1-sp3 | |
Oracle Weblogic Portal | =8.1-sp4 | |
Oracle Weblogic Portal | =8.1-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.