CVE Database · CVE-2008-0864
CVSS v3.1
N/A
EPSS
1.81%
Published
Feb 21, 2008
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.
Weaknesses (CWE)
Affected Products (4)
References (8)