CVE-2008-0864Systems Weblogic Portal vulnerability

CWE-2643 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.4%
top 40.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateMay 1

Description

Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-78g2-xjfj-jhp5: Admin Tools in BEA WebLogic Portal 82022-05-01
CVEList
CVE-2008-0864: Admin Tools in BEA WebLogic Portal 82008-02-21
CVE-2008-0864 — Systems Weblogic Portal vulnerability | cvebase