MEDIUM · 5.0

CVE-2008-0864

Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypa...

Vulnerability Description

Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Bea SystemsWeblogic Portal8.1_sp6
OracleWeblogic Portal8.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-0864?

CVE-2008-0864 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypa...

How severe is CVE-2008-0864?

CVE-2008-0864 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0864?

Check the references section above for vendor advisories and patch information. Affected products include: Bea Systems Weblogic Portal, Oracle Weblogic Portal.