CVE-2007-0415

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/01/2007
Last modified:
09/04/2025

Description

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bea:weblogic_server:*:sp5:*:*:*:*:*:* 8.1 (including)
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*