CVE-2008-0896: Medium severity bea weblogic portal vulnerability
BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0896?
CVE-2008-0896 is considered to have a high severity due to its potential to allow unauthorized access to sensitive content.
How do I fix CVE-2008-0896?
To fix CVE-2008-0896, administrators should apply the latest patches provided by BEA for WebLogic Portal 10.0 and 9.2 MP1.
What versions are affected by CVE-2008-0896?
CVE-2008-0896 affects BEA WebLogic Portal versions 10.0 and 9.2 through MP1.
What type of vulnerability is CVE-2008-0896?
CVE-2008-0896 is a security vulnerability related to improper handling of entitlement policies in BEA WebLogic Portal.
Can CVE-2008-0896 be exploited remotely?
Yes, CVE-2008-0896 can potentially be exploited remotely by attackers to bypass access restrictions.