CVE-2008-0864
Published Feb 21, 2008
Last updated 6 years ago
Overview
- Description
- Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:bea_systems:weblogic_portal:8.1_sp6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "087F8B60-E48C-4DC8-8EBC-EFB614ACBDBF" }, { "criteria": "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DA2A8E6-1BEF-430B-85FD-AFFA44B891CF" }, { "criteria": "cpe:2.3:a:oracle:weblogic_portal:8.1:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF066EF7-82D6-42A4-97AC-C3A71A042152" }, { "criteria": "cpe:2.3:a:oracle:weblogic_portal:8.1:sp5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22257A94-EB2C-432E-A9ED-224D8AB9527F" } ], "operator": "OR" } ] } ]