First published: Thu Feb 21 2008(Updated: )
Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA WebLogic Portal | =8.1_sp6 | |
BEA WebLogic Portal | =8.1-sp3 | |
BEA WebLogic Portal | =8.1-sp4 | |
BEA WebLogic Portal | =8.1-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0864 allows remote attackers to bypass access restrictions due to unintended removal of entitlements when an admin edits a page definition label.
CVE-2008-0864 affects BEA WebLogic Portal versions 8.1 SP3 through SP6.
Mitigation for CVE-2008-0864 involves careful reviewing of page definition changes by administrators to avoid unintended entitlement removals.
CVE-2008-0864 is a unique vulnerability, but similar vulnerabilities often involve privilege escalation or access control issues in web applications.
There is no specific patch for CVE-2008-0864, but updating to a non-vulnerable version of BEA WebLogic Portal is recommended.