Unrated severityNVD Advisory· Published Jan 23, 2007· Updated Apr 23, 2026
CVE-2007-0426
CVE-2007-0426
Description
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.
Affected products
1- cpe:2.3:a:oracle:weblogic_portal:9.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- dev2dev.bea.com/pub/advisory/223nvdPatchVendor Advisory
- secunia.com/advisories/23750nvdVendor Advisory
- osvdb.org/32854nvd
- osvdb.org/38516nvd
- securitytracker.com/idnvd
- www.securityfocus.com/bid/22082nvd
- www.vupen.com/english/advisories/2007/0213nvd
News mentions
0No linked articles in our index yet.