<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel xmlns:cfi="http://www.microsoft.com/schemas/rss/core/2005/internal" lang="en-US" cfi:lastdownloaderror="None"><language>en-US</language><link>http://dev2dev.bea.com/advisoriesnotifications/</link><title cf:type="text">BEA Security Advisories</title><description cf:type="text">Recent BEA security advisories.</description><copyright cf:type="text">Copyright BEA Systems, Inc.</copyright><cf:guid isPermaLink="false">http://dev2dev.bea.com/advisoriesnotifications/</cf:guid><atom:updated>2008-08-25T12:15:06Z</atom:updated><lastBuildDate>Mon, 25 Aug 2008 12:15:06 GMT</lastBuildDate><itunes:author xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns="http://www.w3.org/2005/Atom">BEA's Dev2Dev</itunes:author><itunes:category xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns="http://www.w3.org/2005/Atom" text="Technology" /><itunes:explicit xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns="http://www.w3.org/2005/Atom">no</itunes:explicit><itunes:owner xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns="http://www.w3.org/2005/Atom">
<itunes:name>BEA's Security Advisories</itunes:name>
<itunes:email>secalert@bea.com</itunes:email>
</itunes:owner>
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/beasecurityadvisories" type="application/rss+xml" /><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612450/2800.html</link><title cf:type="text">CVE-2008-3110</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2800.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2800.html" rel="alternate" /><description cf:type="html">
	Security Vulnerability in the Java Runtime Environment Scripting Language Support may allow information disclosure 
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2800.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612451/2799.html</link><title cf:type="text">CVE-2008-3109</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2799.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2799.html" rel="alternate" /><description cf:type="html">
	Security Vulnerability in the Java Runtime Environment Scripting Language Support may allow elevation of privileges 
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2799.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612452/2798.html</link><title cf:type="text">CVE-2008-3108</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2798.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2798.html" rel="alternate" /><description cf:type="html">
	A Security Vulnerability with the processing of fonts in the Java Runtime Environment may allow Elevation of Privileges 
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2798.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612453/2797.html</link><title cf:type="text">CVE-2008-3106</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2797.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2797.html" rel="alternate" /><description cf:type="html">
	Security Vulnerability in the Java Runtime Environment related to the processing of XML Data may result in information disclosure
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2797.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612454/2796.html</link><title cf:type="text">CVE-2008-3105</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2796.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2796.html" rel="alternate" /><description cf:type="html">
	Security Vulnerability in the Java Runtime Environment related to the processing of XML Data may result in information disclosure or denial of service 
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2796.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612455/2795.html</link><title cf:type="text">CVE-2008-3104</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2795.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2795.html" rel="alternate" /><description cf:type="html">
	Security Vulnerabilities in the Java Runtime Environment may allow Same Origin Policy to be Bypassed 
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2795.html</feedburner:origLink></item>

<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/374612456/2794.html</link><title cf:type="text">CVE-2008-3103</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2794.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2794.html" rel="alternate" /><description cf:type="html">
	Security Vulnerability in Java Management Extensions (JMX)
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-08-25T12:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-08-25T12:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2794.html</feedburner:origLink></item>


<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/352363418/3257.html</link><title cf:type="text">CVE-2008-3257</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/3257.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/3257.html" rel="alternate" /><description cf:type="html">
	Security vulnerability in WebLogic plug-in for Apache
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-28T20:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-28T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/3257.html</feedburner:origLink></item>


<item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471890/2782.html</link><title cf:type="text">CVE-2008-2576</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2782.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2782.html" rel="alternate" /><description cf:type="html">
	Information Disclosure vulnerability in the ForeignJMS component
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>31</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2782.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471891/2790.html</link><title cf:type="text">CVE-2008-2577</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2790.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2790.html" rel="alternate" /><description cf:type="html">
	Elevation of privilege vulnerability in the Console/WLST
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>30</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2790.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471892/2789.html</link><title cf:type="text">CVE-2008-2578</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2789.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2789.html" rel="alternate" /><description cf:type="html">
	Information Disclosure vulnerability in the WebLogic console or server log
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>29</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2789.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471893/2785.html</link><title cf:type="text">CVE-2008-2579</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2785.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2785.html" rel="alternate" /><description cf:type="html">
	Information disclosure vulnerability in WebLogic plug-ins for Apache, Sun and IIS Web servers
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>28</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2785.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471894/2786.html</link><title cf:type="text">CVE-2008-2580</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2786.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2786.html" rel="alternate" /><description cf:type="html">
	Information disclosure in JSP pages
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>27</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2786.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471896/2791.html</link><title cf:type="text">CVE-2008-2581</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2791.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2791.html" rel="alternate" /><description cf:type="html">
	Elevation of privilege vulnerabilities in the UDDI Explorer
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>26</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2791.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471897/2792.html</link><title cf:type="text">CVE-2008-2582</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/2792.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/2792.html" rel="alternate" /><description cf:type="html">
	Denial-of-Service vulnerability in WebLogic Server
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-07-15T20:15:06Z</atom:updated><cfi:id>25</cfi:id><cfi:read>false</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-15T19:51:28.170Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/2792.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471899/277.html</link><title cf:type="text">BEA08-201.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/277.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/277.html" rel="alternate" /><description cf:type="html">
	Multiple Security Vulnerabilities in the Java Runtime Environment
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-04-16T19:15:08Z</atom:updated><cfi:id>24</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/277.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471900/264.html</link><title cf:type="text">BEA08-190.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/264.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/264.html" rel="alternate" /><description cf:type="html">
	A WebLogic Portal Administration Console session can inadvertently redirect from https port to an http port
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>23</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/264.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471901/265.html</link><title cf:type="text">BEA08-191.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/265.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/265.html" rel="alternate" /><description cf:type="html">
	Tampering HTML request headers could lead to an elevation of privileges
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>22</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/265.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471903/266.html</link><title cf:type="text">BEA08-192.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/266.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/266.html" rel="alternate" /><description cf:type="html">
	When content portlets are deleted from one of the portal?s pages, all entitlements are removed for the application
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>21</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/266.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471904/267.html</link><title cf:type="text">BEA08-193.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/267.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/267.html" rel="alternate" /><description cf:type="html">
	Non-authorized user may be able to receive messages from a secured JMS Topic destination
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>20</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/267.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471905/268.html</link><title cf:type="text">BEA08-194.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/268.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/268.html" rel="alternate" /><description cf:type="html">
	A non-authorized user may be able to send messages to a protected distributed queue
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>19</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/268.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471913/269.html</link><title cf:type="text">BEA08-195.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/269.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/269.html" rel="alternate" /><description cf:type="html">
	Cross-site scripting vulnerability in Console?s Unexpected Exception Page
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>18</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/269.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471914/270.html</link><title cf:type="text">BEA08-196.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/270.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/270.html" rel="alternate" /><description cf:type="html">
	A session fixation exploit could result in elevated privileges
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>17</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/270.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471915/256.html</link><title cf:type="text">BEA08-183.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/256.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/256.html" rel="alternate" /><description cf:type="html">
	Security policies on a WebLogic Portal Page can inadvertently be lost by an administrator performing certain editing operations on that page
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>16</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/256.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471917/257.html</link><title cf:type="text">BEA08-184.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/257.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/257.html" rel="alternate" /><description cf:type="html">
	An entitlement on an instance of a floatable portlet can be bypassed
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>15</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/257.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471918/258.html</link><title cf:type="text">BEA08-185.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/258.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/258.html" rel="alternate" /><description cf:type="html">
	Cross-site scripting (XSS) vulnerabilities in Web applications using WebLogic Workshop NetUI page flows
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>14</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/258.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471925/259.html</link><title cf:type="text">BEA08-186.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/259.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/259.html" rel="alternate" /><description cf:type="html">
	BEA Plumtree Portal cross site scripting (XSS) vulnerability
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>13</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/259.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471927/260.html</link><title cf:type="text">BEA08-187.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/260.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/260.html" rel="alternate" /><description cf:type="html">
	Web Service WSDL and policy is exposed to unauthenticated HTTP clients
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>12</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/260.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471931/261.html</link><title cf:type="text">BEA08-188.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/261.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/261.html" rel="alternate" /><description cf:type="html">
	JavaScript can be injected into the WLP Groupspace application and can allow for an XSS exploit
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>11</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/261.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471932/262.html</link><title cf:type="text">BEA08-110.01</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/262.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/262.html" rel="alternate" /><description cf:type="html">
	Cleartext database password in the config.xml file
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>10</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/262.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471933/263.html</link><title cf:type="text">BEA08-189.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/263.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/263.html" rel="alternate" /><description cf:type="html">
	Cross-site scripting (XSS) vulnerabilities in Web applications using either WebLogic Workshop NetUI or Apache Beehive NetUI page flows
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2008-02-19T19:45:07Z</atom:updated><cfi:id>9</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/263.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471934/255.html</link><title cf:type="text">BEA07-182.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/255.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/255.html" rel="alternate" /><description cf:type="html">
	Application files and resources may be remotely accessed
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-12-12T19:15:10Z</atom:updated><cfi:id>8</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/255.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471935/254.html</link><title cf:type="text">BEA07-181.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/254.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/254.html" rel="alternate" /><description cf:type="html">
	BEA Plumtree Foundation search facility allows an unauthenticated guest user to search for user objects
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-12-01T02:45:13Z</atom:updated><cfi:id>7</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/254.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471936/252.html</link><title cf:type="text">BEA07-180.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/252.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/252.html" rel="alternate" /><description cf:type="html">
	BEA Plumtree Foundation full version vulnerability
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-12-01T02:45:13Z</atom:updated><cfi:id>6</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/252.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471937/251.html</link><title cf:type="text">BEA07-179.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/251.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/251.html" rel="alternate" /><description cf:type="html">
	BEA Plumtree Foundation internal hostname disclosure vulnerability
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-12-01T02:45:13Z</atom:updated><cfi:id>5</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/251.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471938/247.html</link><title cf:type="text">BEA07-148.01</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/247.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/247.html" rel="alternate" /><description cf:type="html">
	Malformed headers may cause high disk consumption
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-08-28T18:45:06Z</atom:updated><cfi:id>4</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/247.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471939/246.html</link><title cf:type="text">BEA07-87.02</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/246.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/246.html" rel="alternate" /><description cf:type="html">
	A malicious client can cause threads to hang on the server.
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-08-28T18:45:06Z</atom:updated><cfi:id>3</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/246.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471940/244.html</link><title cf:type="text">BEA07-175.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/244.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/244.html" rel="alternate" /><description cf:type="html">
	SSL clients may not find all possible cipher suites resulting in use of the default null cipher (no encryption)
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-08-28T18:45:06Z</atom:updated><cfi:id>2</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/244.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471941/245.html</link><title cf:type="text">BEA07-176.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/245.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/245.html" rel="alternate" /><description cf:type="html">
	Server may select a cipher suite that uses a null cipher for SSL communication with SSL clients
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-08-28T18:45:06Z</atom:updated><cfi:id>1</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/245.html</feedburner:origLink></item><item><link>http://feeds.feedburner.com/~r/beasecurityadvisories/~3/351471942/248.html</link><title cf:type="text">BEA07-177.00</title><guid isPermaLink="false">https://support.bea.com/application_content/product_portlets/securityadvisories/248.html</guid><atom:link href="https://support.bea.com/application_content/product_portlets/securityadvisories/248.html" rel="alternate" /><description cf:type="html">
	Multiple Security Vulnerabilities in the Java Runtime Environment
	</description><author>BEA's Dev2Dev</author><atom:author><atom:name>BEA's Dev2Dev</atom:name></atom:author><atom:updated>2007-08-28T18:45:06Z</atom:updated><cfi:id>0</cfi:id><cfi:read>true</cfi:read><cfi:downloadurl>https://support.bea.com/application_content/product_portlets/pub/feed/31.html</cfi:downloadurl><cfi:lastdownloadtime>2008-07-11T16:06:07.299Z</cfi:lastdownloadtime><feedburner:origLink>https://support.bea.com/application_content/product_portlets/securityadvisories/248.html</feedburner:origLink></item></channel></rss>
