Release Date: 2008-10-15
Critical:
Moderately critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: BEA WebLogic Workshop 8.x
Description:
A vulnerability has been reported in BEA WebLogic Workshop, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an unspecified error within NetUI pageflows, which can be exploited to access restricted information.
Solution:
Upgrade to WebLogic Workshop Service Pack 6 or a newer version (9.2 or later).
http://www.oracle.com/technology/software/products/ias/bea_main.html
Provided and/or discovered by:
Reported by the vendor.
Original Advisory:
https://support.bea.com/application_c...portlets/securityadvisories/2805.html
BEA WebLogic Server Multiple Authorizers Security Bypass
Release Date: 2008-10-15
Critical:
Moderately critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch
Software: BEA WebLogic Server 9.x
Description:
A vulnerability has been reported in BEA WebLogic Server, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerability is caused due to an unspecified error related to the use of multiple authorizers (e.g. a XACMLAuthorizer and a DefaultAuthorizer) can be exploited to bypass certain security restrictions.
The vulnerability is reported in Oracle WebLogic Server 9.1.
Solution:
Use the Smart Update tool to install the 9.1 patch for CR334468.
Provided and/or discovered by:
Reported by the vendor.
Original Advisory:
https://support.bea.com/application_c...portlets/securityadvisories/2802.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic