BEA WebLogic contains a flaw that may lead to an administrator believing that a new security provider has been activated even though it is not active yet. This is because WebLogic does not activate a security provider before the system is rebooted. This may lead to a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Other
Impact:
Impact Unknown
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.