5

CVE-2006-1358

Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.

Data is provided by the National Vulnerability Database (NVD)
OracleWeblogic Portal Version8.1
OracleWeblogic Portal Version8.1 Updatesp1
OracleWeblogic Portal Version8.1 Updatesp2
OracleWeblogic Portal Version8.1 Updatesp3
OracleWeblogic Portal Version8.1 Updatesp4
OracleWeblogic Portal Version8.1 Updatesp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.646
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N