PT-2007-1897 · Bea · Bea Weblogic Portal+1
Published
2007-01-23
·
Updated
2018-10-30
·
CVE-2007-0426
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Portal version 9.2
Description
The issue arises when BEA WebLogic Portal 9.2 is running in a WebLogic Server clustered environment and utilizing WebLogic Portal entitlements. If entitlement policy changes are made on a managed server while the Administrative Server is unavailable, these changes are not properly propagated, potentially allowing attackers to bypass intended restrictions.
Recommendations
For BEA WebLogic Portal version 9.2, ensure that entitlement policy changes are made when the Administrative Server is available to properly propagate these changes across the clustered environment. As a temporary workaround, consider restricting changes to entitlement policies until the Administrative Server is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Portal
Oracle Weblogic Server