Total vulnerabilities in the database
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.
Software | From | Fixed in |
---|---|---|
bea_systems / weblogic_portal | 9.2-mp2 | 9.2-mp2.x |
bea_systems / weblogic_portal | 10.0 | 10.0.x |
bea_systems / weblogic_portal | 9.2-mp1 | 9.2-mp1.x |
oracle / weblogic_portal | 9.2 | 9.2.x |