BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.
References
Link | Resource |
---|---|
http://dev2dev.bea.com/pub/advisory/236 | Patch Vendor Advisory |
http://osvdb.org/36065 | |
http://secunia.com/advisories/25284 | Vendor Advisory |
http://www.securitytracker.com/id?1018060 | Vendor Advisory |
http://www.vupen.com/english/advisories/2007/1815 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34285 | |
http://dev2dev.bea.com/pub/advisory/236 | Patch Vendor Advisory |
http://osvdb.org/36065 | |
http://secunia.com/advisories/25284 | Vendor Advisory |
http://www.securitytracker.com/id?1018060 | Vendor Advisory |
http://www.vupen.com/english/advisories/2007/1815 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34285 |
Configurations
History
21 Nov 2024, 00:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://dev2dev.bea.com/pub/advisory/236 - Patch, Vendor Advisory | |
References | () http://osvdb.org/36065 - | |
References | () http://secunia.com/advisories/25284 - Vendor Advisory | |
References | () http://www.securitytracker.com/id?1018060 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2007/1815 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34285 - |
Information
Published : 2007-05-16 01:19
Updated : 2024-11-21 00:31
NVD link : CVE-2007-2703
Mitre link : CVE-2007-2703
CVE.ORG link : CVE-2007-2703
JSON object : View
Products Affected
oracle
- weblogic_portal
CWE