CVE-2008-0864: Medium severity bea weblogic portal vulnerability
Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2008-0864?
CVE-2008-0864 allows remote attackers to bypass access restrictions due to unintended removal of entitlements when an admin edits a page definition label.
Which versions of BEA WebLogic Portal are affected by CVE-2008-0864?
CVE-2008-0864 affects BEA WebLogic Portal versions 8.1 SP3 through SP6.
How can I mitigate CVE-2008-0864?
Mitigation for CVE-2008-0864 involves careful reviewing of page definition changes by administrators to avoid unintended entitlement removals.
What are the known vulnerabilities similar to CVE-2008-0864?
CVE-2008-0864 is a unique vulnerability, but similar vulnerabilities often involve privilege escalation or access control issues in web applications.
Is there a patch available for CVE-2008-0864?
There is no specific patch for CVE-2008-0864, but updating to a non-vulnerable version of BEA WebLogic Portal is recommended.