CVE Vulnerabilities

CVE-2007-0415

Published: Jan 23, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea * 8.1 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)

References