BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_portal | Bea_systems | 9.2-mp1 (including) | 9.2-mp1 (including) |
Weblogic_portal | Bea_systems | 10.0 (including) | 10.0 (including) |