BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
Link | Tags |
---|---|
http://www.secunia.com/advisories/9232/ | third party advisory patch vendor advisory |
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp |