|
CVE Reference: CVE-2008-0896
|
|
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.
|
|
Original Page at CVE MITRE:
CVE-2008-0896
|
|
Description:
BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.
|
|
CVE Status:
Candidate
|
|
References:
ST 1019453
SAID Secunia Advisory: SA29041
BEA http://dev2dev.bea.com/pub/advisory/266
|
|
|
Return to the previous page.
|