BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Weblogic_server | Bea | * | 8.1 (including) |
| Weblogic_server | Bea | 8.1 (including) | 8.1 (including) |