
CVE-2008-0864
https://notcve.org/view.php?id=CVE-2008-0864
21 Feb 2008 — Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions. Admin Tools en BEA WebLogic Portal 8.1 SP3 al SP6, involuntariamente puede eliminar los derechos para páginas cuando un administrador edita la etiqueta de definición de página, que podría permitir a atacantes remotos evitar las restricciones de acceso planeadas. • http://dev2dev.bea.com/pub/advisory/256 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-0865
https://notcve.org/view.php?id=CVE-2008-0865
21 Feb 2008 — Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors. Vulnerabilidad no especificada en BEA WebLogic Portal 8.1 hasta SP6 permite a atacantes remotos evitar los derechos para las instancias de un portlet WLP flotable mediante vectores desconocidos. • http://dev2dev.bea.com/pub/advisory/257 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2006-1358
https://notcve.org/view.php?id=CVE-2006-1358
22 Mar 2006 — Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user. • ftp://ftpna.beasys.com/pub/releases/security/patch_CR259534_81SP5.zip •

CVE-2006-0423
https://notcve.org/view.php?id=CVE-2006-0423
25 Jan 2006 — BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges. • http://dev2dev.bea.com/pub/advisory/167 •

CVE-2006-0425
https://notcve.org/view.php?id=CVE-2006-0425
25 Jan 2006 — BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors. • http://dev2dev.bea.com/pub/advisory/169 •

CVE-2006-0428
https://notcve.org/view.php?id=CVE-2006-0428
25 Jan 2006 — Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs. • http://dev2dev.bea.com/pub/advisory/172 •

CVE-2005-2680
https://notcve.org/view.php?id=CVE-2005-2680
23 Aug 2005 — Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs. • http://dev2dev.bea.com/pub/advisory/137 •