4.9
CVSSv2

CVE-2008-0896

Published: 22/02/2008 Updated: 08/03/2011
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows malicious users to bypass intended access restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

bea systems weblogic portal 9.2

bea systems weblogic portal 10.0