CVE-2008-0870
BEA WebLogic Portal 9.2-10.0 - Session Hijacking via HTTPS to HTTP Redirect
Title source: llmDescription
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.
References (4)
Core 4
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0613
Patch vendor-advisory
x_refsource_bea
http://dev2dev.bea.com/pub/advisory/264
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/29041
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1019442
Scores
EPSS
0.0143
EPSS Percentile
69.6%
Details
CWE
CWE-59
Status
published
Products (3)
bea_systems/weblogic_portal
9.2 mp1 (2 CPE variants)
bea_systems/weblogic_portal
10.0
oracle/weblogic_portal
9.2
Published
Feb 21, 2008
Tracked Since
Feb 18, 2026