5

CVE-2008-0864

Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea Systems ≫ Weblogic Portal Version 8.1_sp6
Oracle ≫ Weblogic Portal Version 8.1 Update sp3
Oracle ≫ Weblogic Portal Version 8.1 Update sp4
Oracle ≫ Weblogic Portal Version 8.1 Update sp5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.81% 0.758
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.vupen.com/english/advisories/2008/0613
http://secunia.com/advisories/29041
http://dev2dev.bea.com/pub/advisory/256
http://www.securitytracker.com/id?1019454