
CIA RESEARCH
Alerts
[CIA-1035-Alert] WebLogic Portal Access Control
Vulnerability allows access to restricted pages
Summary:
A vulnerability in WebLogic Portal allows
unauthorized access to bypass access controls based on entitlements.
Technical Details:
A vulnerability WebLogic Portal versions 8.1 through SP4
allows a remote user to bypass entitlement restrictions and access content that
would ordinarily be restricted based on their entitlements. By maliciously crafting a
URL it is possible to bypass all entitlement restrictions for a particular resource,
which could result in an exposure of confidential information, and possibly provide a
means to leverage additional access to the server. Any system with entitlements placed
directly upon WebLogic resources (e.g. desktop books, pages, portlets) is affected.
Solution:
Apply the security fix provided at the link below:
ftp://ftpna.beasys.com/pub/releases/security/ patch_CR238578_81SP4.zip
CVE Reference:
GENERIC-MAP-NOMATCH
SecurityTracker Number(s):
1014759
Vendor URL:
www.bea.com
About the Cenzic CIA Team:
Cenzic Intelligent Analysis (CIA) is Cenzic’s
research arm that focuses on continuous research for application vulnerabilities.
Industry Research, Vulnerability assessment, penetration testing, and security
testing — that’s what Cenzic Intelligent Analysis Research is all about.
Cenzic has dedicated experts whose sole job is to perform ongoing research to
find not only common vulnerabilities but also vulnerabilities found in customer
applications and make them available to our customers and to the community at large.
About Cenzic:
Cenzic provides Hailstorm® the revolutionary enterprise
software suite for automated application security assessment and compliance that
allows corporations and government organizations to dramatically improve the
security of commercial and custom applications. Hailstorm enables security experts,
QA professionals, and developers to work together to assess, analyze, and remediate
applications for security vulnerabilities, and verify compliance with security policies.
Benefits include reduced security risk and liability, lower development and testing
costs, and faster time-to-market. Cenzic’s customers are currently in the financial
services and e-marketplaces sectors. For more information visit www.cenzic.com or call 1-866-4-CENZIC

|