CVE-2004-0713 Information

Description

The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2 7.0 through SP4 and 6.1 through SP6 does not properly check EJB permissions before unexporting a bean which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.

Reference

http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp http://www.kb.cert.org/vuls/id/658878 http://www.securityfocus.com/bid/10185 https://exchange.xforce.ibmcloud.com/vulnerabilities/15928

Share on: