Description
BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.
Affected products
- bea_systems / weblogic_portal9.2 – 9.2
- bea_systems / weblogic_portal10.0 – 10.0