CVE-2004-0470 Information
Feb 14, 2021
cve
Description
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag which can remove intended access restrictions for the associated web application.
Reference
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp http://secunia.com/advisories/11593 http://securitytracker.com/id?1010128 http://www.kb.cert.org/vuls/id/950070 http://www.osvdb.org/6076 http://www.securityfocus.com/bid/10328 https://exchange.xforce.ibmcloud.com/vulnerabilities/16123
Share on: