Oracle WebLogic Portal 9.2 GA

CPE Details

Oracle WebLogic Portal 9.2 GA
9.2
2011-01-18
18h38 +00:00
2011-01-18
18h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:oracle:weblogic_portal:9.2:ga:*:*:*:*:*:*

Informations

Vendor

oracle

Product

weblogic_portal

Version

9.2

Update

ga

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2008-0868 2008-02-21 00h00 +00:00 Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.
4.3
CVE-2008-0870 2008-02-21 00h00 +00:00 BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.
7.5
CVE-2007-5576 2007-10-18 19h00 +00:00 BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
6.8
CVE-2007-2702 2007-05-15 23h00 +00:00 Cross-site scripting (XSS) vulnerability in the GroupSpace application in BEA WebLogic Portal 9.2 GA allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the rich text editor.
3.5
CVE-2007-2703 2007-05-15 23h00 +00:00 BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.
3.6
CVE-2007-0423 2007-01-22 23h00 +00:00 BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.
4.4
CVE-2007-0426 2007-01-22 23h00 +00:00 BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.
6.8