Vulnerabilities > CVE-2007-0426 - Unspecified vulnerability in Oracle Weblogic Portal 9.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://dev2dev.bea.com/pub/advisory/223
- http://dev2dev.bea.com/pub/advisory/223
- http://osvdb.org/32854
- http://osvdb.org/32854
- http://osvdb.org/38516
- http://osvdb.org/38516
- http://secunia.com/advisories/23750
- http://secunia.com/advisories/23750
- http://securitytracker.com/id?1017521
- http://securitytracker.com/id?1017521
- http://www.securityfocus.com/bid/22082
- http://www.securityfocus.com/bid/22082
- http://www.vupen.com/english/advisories/2007/0213
- http://www.vupen.com/english/advisories/2007/0213