Description
BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-0903 | BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:01:40.095Z
Reserved: 2008-02-22T00:00:00.000Z
Link: CVE-2008-0896
No data.
Status : Modified
Published: 2008-02-22T21:44:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-0896
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD