Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BEA WebLogic Server 和WebLogic Express漏洞
Vulnerability Description
当使用WebLogic Builder或者SecurityRoleAssignmentMBean.toXML方法编辑weblogic.xml时,BEA WebLogic Server和WebLogic Express 7.0到SP5 和8.1到SP2版本在weblogic.xml没有principal-name标签时不注意地清除security-role-assignment标签。这能够清除web应用相关的有意访问限制。
CVSS Information
N/A
Vulnerability Type
N/A