CVE-2008-0870

BEA WebLogic Portal 9.2-10.0 - Session Hijacking via HTTPS to HTTP Redirect

Title source: llm
STIX 2.1

Description

BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0613
Patch vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/264
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29041
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019442

Scores

EPSS 0.0143
EPSS Percentile 69.6%

Details

CWE
CWE-59
Status published
Products (3)
bea_systems/weblogic_portal 9.2 mp1 (2 CPE variants)
bea_systems/weblogic_portal 10.0
oracle/weblogic_portal 9.2
Published Feb 21, 2008
Tracked Since Feb 18, 2026