|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
A remote unauthorized access flaw exists in BEA WebLogic Portal Web Services Remote Portlets (WSRP). Certain carefully crafted URLs' might allow a remote user to access unintended web resources even if those resources are located behind a firewall. Any site using Web Services Remote Portlets (WSRP) of WebLogic Portal are susceptible to this vulnerability.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to v8.1 SP5. In addition, BEA Systems has released a patch for it, which needs to be applied once the upgrade to SP5 is done. WebLogic Portal 8.1 Service Pack 6 will include the functionality in this patch.
|
|
Products |
|
Portal
 |
8.1 Service Pack 3 |
8.1 Service Pack 4 |
8.1 Service Pack 5 |
|
|
|
|
Credit |
- EPAM Systems - EPAM Systems
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|