BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_server | Bea | * | 8.1 (including) |
Weblogic_server | Bea | 8.1 (including) | 8.1 (including) |