[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253741

 
 

909

 
 

197391

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0715Date: (C)2004-07-27   (M)2023-12-22


The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1009763
BID-10130
SECUNIA-11356
OSVDB-5299
VU#470470
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_52.01.jsp
weblogic-authentication-gain-privileges(15861)

CPE    8
cpe:/a:bea:weblogic_server:8.1:sp2:win32
cpe:/a:bea:weblogic_server:8.1:sp1:express
cpe:/a:bea:weblogic_server:8.1
cpe:/a:bea:weblogic_server:7.0
...

© SecPod Technologies