CVE-2007-0426 Information
Feb 14, 2021
cve
Description
BEA WebLogic Portal 9.2 when running in a WebLogic Server clustered environment using WebLogic Portal entitlements does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable which might allow attackers to bypass intended restrictions.
Reference
http://dev2dev.bea.com/pub/advisory/223 http://osvdb.org/32854 http://osvdb.org/38516 http://secunia.com/advisories/23750 http://securitytracker.com/id?1017521 http://www.securityfocus.com/bid/22082 http://www.vupen.com/english/advisories/2007/0213
Share on: