CVE-2008-0865: Medium severity bea weblogic portal vulnerability
Published Feb 21, 2008
·Updated
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors.
Affected Software
7 affected components
Bea Systems Weblogic Portal=8.1_sp6
Oracle Weblogic Portal=8.1
Oracle Weblogic Portal=8.1-sp1
Oracle Weblogic Portal=8.1-sp2
Oracle Weblogic Portal=8.1-sp3
Oracle Weblogic Portal=8.1-sp4
Oracle Weblogic Portal=8.1-sp5
Event History
Feb 21, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the nature of CVE-2008-0865?
CVE-2008-0865 is a vulnerability in BEA WebLogic Portal that allows remote attackers to bypass entitlements for instances of a floatable WLP portlet.
2
What versions of BEA WebLogic Portal are affected by CVE-2008-0865?
CVE-2008-0865 affects BEA WebLogic Portal versions 8.1 through SP6.
3
How can I mitigate the risks associated with CVE-2008-0865?
To mitigate CVE-2008-0865, it is recommended to apply the latest security patches or updates from the vendor.
4
What type of attack does CVE-2008-0865 enable?
CVE-2008-0865 enables remote attackers to manipulate entitlements within the WebLogic Portal.
5
Is there a workaround for CVE-2008-0865 if I cannot immediately apply a patch?
While no specific workarounds are provided, it is advisable to restrict access to vulnerable portlets until a patch can be applied.