Overview
There is a vulnerability in the BEA WebLogic Server that could allow the unauthorized removal of an Enterprise JavaBean (EJB).
Description
BEA Systems describes WebLogic Server as "an industrial-strength application infrastructure for developing, integrating, securing, and managing distributed Java applications." The WebLogic server supports the use of Enterprise JavaBean (EJB) applications. EJB is a component architecture used for building distributed, object-oriented business applications. When designing an EJB application, there are various methods used to provide an interface with the WebLogic Server. There is a vulnerability in the way WebLogic Server handles calls to the remove() method. When an application implements this remove() method, the application can remove a stateful EJB object from a remote view even if that application does not have permission to remove it.
|
Impact
Enterprise JavaBean applications implementing the remove() method could allow unauthorized users to remove EJB objects from remote views. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
This vulnerability was reported by BEA Systems Inc.
This document was written by Damon Morda.
Other Information
| CVE IDs: | None |
| Severity Metric: | 3.90 |
| Date Public: | 2004-04-21 |
| Date First Published: | 2004-04-23 |
| Date Last Updated: | 2004-04-23 18:15 UTC |
| Document Revision: | 19 |