Required CVE Record Information
Description
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, might allow local users to gain privileges by using the run-as deployment descriptor element to change the privileges of a web application or EJB from the Deployer security role to the Admin security role.
References 3 Total
- securityfocus.com: 15052 vdb-entry
- secunia.com: 17138 third-party-advisory
- dev2dev.bea.com: BEA05-88.00 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- securityfocus.com: 15052 vdb-entryx_transferred
- secunia.com: 17138 third-party-advisoryx_transferred
- dev2dev.bea.com: BEA05-88.00 vendor-advisoryx_transferred