| Vulnerability Name: | CVE-2008-5462 (CCN-48002) | ||||||||
| Assigned: | 2008-12-11 | ||||||||
| Published: | 2009-01-13 | ||||||||
| Updated: | 2012-10-23 | ||||||||
| Summary: | Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. See following link for more information: https://support.bea.com/application_content/product_portlets/securityadvisories/2808.html | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-5462 Source: CCN Type: SECTRACK ID: 1021571 WebLogic Bugs Let Remote Users Execute Arbitary Code, Acces and Modify Information, and Deny Service Source: CCN Type: ASPR #2009-01-27-1 HTML Injection in BEA WebLogic Server Console Source: CCN Type: Oracle Critical Patch Update Advisory - January 2009 Oracle Critical Patch Update Advisory - January 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.html Source: CCN Type: OSVDB ID: 51316 Oracle BEA WebLogic Portal Administration Console Unspecified XSS Source: BID Type: UNKNOWN 33177 Source: CCN Type: BID-33177 Oracle January 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1021571 Source: VUPEN Type: UNKNOWN ADV-2009-0115 Source: XF Type: UNKNOWN oracle-weblogic-portal-xss(48002) Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2008-5462) Elevation of privilege vulnerability in WebLogic Portal | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||