BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_portal | Bea_systems | 9.2-mp1 (including) | 9.2-mp1 (including) |
Weblogic_portal | Bea_systems | 9.2-mp2 (including) | 9.2-mp2 (including) |
Weblogic_portal | Bea_systems | 10.0 (including) | 10.0 (including) |
Weblogic_portal | Oracle | 9.2 (including) | 9.2 (including) |