Overview
There is a vulnerability in the BEA WebLogic Server that could allow the unauthorized removal of an Enterprise JavaBean (EJB).
Description
BEA Systems describes WebLogic Server as "an industrial-strength application infrastructure for developing, integrating, securing, and managing distributed Java applications." The WebLogic server supports the use of Enterprise JavaBean (EJB) applications. EJB is a component architecture used for building distributed, object-oriented business applications. When designing an EJB application, there are various methods used to provide an interface with the WebLogic Server. There is a vulnerability in the way WebLogic Server handles calls to the remove() method. When an application implements this remove() method, the application can remove a stateful EJB object from a remote view even if that application does not have permission to remove it.
|
Impact
Enterprise JavaBean applications implementing the remove() method could allow unauthorized users to remove EJB objects from remote views. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by BEA Systems Inc.
This document was written by Damon Morda.
Other Information
CVE IDs: | None |
Severity Metric: | 3.90 |
Date Public: | 2004-04-21 |
Date First Published: | 2004-04-23 |
Date Last Updated: | 2004-04-23 18:15 UTC |
Document Revision: | 19 |