Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BEA WebLogic Server 安全策数组参数权限提升漏洞
Vulnerability Description
BEA WebLogic Server 7.0到7.0 SP6,8.1到8.1 SP5,9.0和9.1没有执行为EJB方式宣称许可的安全策略,这使得远程攻击者可以对这些方式的未授权访问。EJB方式含有数组参数。
CVSS Information
N/A
Vulnerability Type
N/A