BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.
                
            References
                    | Link | Resource | 
|---|---|
| http://dev2dev.bea.com/pub/advisory/236 | Patch Vendor Advisory | 
| http://osvdb.org/36065 | |
| http://secunia.com/advisories/25284 | Vendor Advisory | 
| http://www.securitytracker.com/id?1018060 | Vendor Advisory | 
| http://www.vupen.com/english/advisories/2007/1815 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/34285 | |
| http://dev2dev.bea.com/pub/advisory/236 | Patch Vendor Advisory | 
| http://osvdb.org/36065 | |
| http://secunia.com/advisories/25284 | Vendor Advisory | 
| http://www.securitytracker.com/id?1018060 | Vendor Advisory | 
| http://www.vupen.com/english/advisories/2007/1815 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/34285 | 
Configurations
                    History
                    No history.
Information
                Published : 2007-05-16 01:19
Updated : 2025-04-09 00:30
NVD link : CVE-2007-2703
Mitre link : CVE-2007-2703
CVE.ORG link : CVE-2007-2703
JSON object : View
Products Affected
                oracle
- weblogic_portal
CWE
                