Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_portal | Oracle | 8.1 (including) | 8.1 (including) |
Weblogic_portal | Oracle | 8.1-sp1 (including) | 8.1-sp1 (including) |
Weblogic_portal | Oracle | 8.1-sp2 (including) | 8.1-sp2 (including) |
Weblogic_portal | Oracle | 8.1-sp3 (including) | 8.1-sp3 (including) |
Weblogic_portal | Oracle | 8.1-sp4 (including) | 8.1-sp4 (including) |
Weblogic_portal | Oracle | 8.1-sp5 (including) | 8.1-sp5 (including) |