CVE Database
/

CVE-2004-0470

Back to search

CVE-2004-0470

Published: May 20, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.

VendorProductVersions

n/a

n/a

affected
n/a

References

11593
third-party-advisory
x_refsource_SECUNIA
1010128
vdb-entry
x_refsource_SECTRACK
6076
vdb-entry
x_refsource_OSVDB
VU#950070
third-party-advisory
x_refsource_CERT-VN
10328
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now