VulnerabilityModified
CVE-2005-2680
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.
MEDIUM 5.0EPSS 3.45%
Does this matter?
Lower severity and a low EPSS score (3.45%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- oracle/weblogic portal
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/137Patch, Vendor Advisory
- http://dev2dev.bea.com/pub/advisory/137Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.