Looks like Big Time BUG: WebLogic 10.3 someone it can be planted at any time. Beware!

Hello

I played just with tree JNDI of WLS10.3.0 server... by example: http://weblogic-wonders.com/weblogic/2010/06/12/binding-objects-in-weblogic-servers-jndi-tree/. In the above example, I tried to bind an object employee... u can try to bind a Simple string.

And found that WebLogic JNDI tree is not at all safe... One without credentials can bind 10000 s object server JNDI tree... Who will be fiillup the server with a thousand large objects...


If you are an admin... so be aware of this... And file a BUG report. Or else who knows the URL of your server can fill the job with thousands of objects at any time. < color = red > < h4 > imagine anyone who knows the URL of your server can trigger a complete program of your servers heap with 10000 s Garbage objects like this... and can make your server CRY. All by tying a very long string in JNDI servers... tree several times < / police > < / h4 >


IDEAL behavior should be:
Until the valid credentials u pass the WLS should alow allows you to bind one object in the JNDI tree...:
< color = red > < h4 >
env.put (Context.SECURITY_PRINCIPAL", adminUsername");
env.put (Context.SECURITY_CREDENTIALS, "adminPassword");
< / police > < / h4 >
.
.
Thank you
Jay SenSharma

Joy,

As a solution we can guarantee the JNDI using the admin role.
I made a post about it and posted some screenshots on the wonders of weblogic.

http://WebLogic-wonders.com/WebLogic/2010/06/14/securing-the-JNDI-with-Admin-role-in-11g/

Tags: Fusion Middleware

Similar Questions

  • Is there a way to tell Firefox to reload a page every time? I am a web designer and need to see what it looks like every time I open the pages that I do.

    In Internet Explorer, you can configure the program to reload a web page each time you visit a page. I can't find a way to do it in FF. I prefer to only reload the Web sites that I work on rather than on the web, but it's probably not possible with any browser.

    Win 7 - x 64
    16 GB OF RAM
    ATI Radeon HD 5670

    Thanks for any help one can offer!

    You can also reload webpages and ignore the cache to refresh potentially stale or corrupt.

    • Hold down the SHIFT key and click the Reload button
    • Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
    • Press 'Command + shift + R' (Mac)
  • I need free space in my Mac Air looking at 'about my Mac"it looks like I have 40 GB as backup, but I can't find it with the ODS

    I need free space in my Mac Air

    I used "about my Mac' and TI - s telling me I have 40 GB as backup, but I can't find with ODS (OmniDiskSweeper)

    ODS tells me I have just 30-40 GB busy.

    I can find a way to release the backup file?

    I m also helps TimeCapsule and back up there it's only 30-40 GB (as the ODS is to find)

    appreciate the help

    It seems to me that you look at the Snapshots Time Machine:

    https://support.Apple.com/en-us/HT204015

    You can ignore them.

    If they bother you, find the instructions to put out them here:

    http://pondini.org/TM/30.html

    Ciao.

  • my computer looks like an echo chamber... . How can I change?

    My sounds Windows Vista as a room of echo and I don't know how to change it. Help?

    Please try to disable all audio enhancements and update sound card drivers, as suggested in the

    http://Windows.Microsoft.com/en-us/Windows-Vista/how-do-I-stop-my-music-from-skipping-or-breaking-up-when-I-play-it

    Who help me?

  • I don't know how but I lost my Adobe cloud on my computer. I still well as Lightroom. Looks like he wanted to put it on my phone but I don't want it

    I lost my benlahcenne cloud on my computer. Looks like he wants to on this phone. How can I get on my computer. The only thing in applications is an uninstall option. How can I get it back?

    Sign out of your account of cloud... Restart your computer... Connect to your paid account of cloud

    -Connect using http://helpx.adobe.com/x-productkb/policy-pricing/account-password-sign-faq.html

    -https://helpx.adobe.com/creative-cloud/help/sign-in-out-activate-apps.html

    -http://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html

    -https://helpx.adobe.com/x-productkb/policy-pricing/activate-deactivate-products.html

    Download & install instructions https://forums.adobe.com/thread/2003339 can help

    -includes a link to access a page to download the Adobe programs if you do not have a disk or drive

    - or kglad links in response to #1 here can help https://forums.adobe.com/thread/2017859

    Also go to https://forums.adobe.com/community/creative_cloud/creative_cloud_faq

    - and also read https://forums.adobe.com/thread/1146459

  • JTabbedPane: 1 tablet should look like from JPanel

    Does anyone know a way how to do a JTabbedPane look like in a JPanel if there is only 1 tablet, but if it has more than 1 tablet to it, it looks like a tabbed pane? In other words: How can I make the button bar disappear if there is only 1 Tablet?

    Thank you very much for your help! :)

    JTabbedPane does not support that. Http://java.net/projects/jide-oss/ JideTabbedPane done.

    If you want to paste JTabbedPane you could do it with a change listener and a CardLayout and switch cards when there is only a single tab (the last content tab reparenting).

  • every time I open Firefox I get this horrible game video music blasting. Looks like PacMan. On a Macbook.

    Whenever I open Firefox on my Macbook, I get video game music blasting. Looks like PacMan.

    This has happened

    Each time Firefox opened

    Is today

    We were able to resolve the problem by disabling the "Cool Preview' add-in Mac OS x 10.4.

  • I have a Server R2 windows 2012 automatically switches out of his own for several times and it doesn't look like a hardware problem.

    I have a windows server R2 2012 which automatically switches out of his own for several times and it doesn't look like a hardware problem. and I have this problem every day.please tell me what is the reason

    Original title: r2 windows server 2012

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.technet.Microsoft.com/forums/en-us/home

    http://social.msdn.Microsoft.com/forums/en-us/home

  • Select start_with - connect in XML document (it looks like a bug in 11.2 g)

    Hello

    I really have no idea of what is the difference between these two cases and why one does not return anything. I have an xml document:

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?><dirObjects>
        <DIR_OBJECT>
            <ABSOLUTE_PATH>/home/pavel/Templates</ABSOLUTE_PATH>
            <OBJ_ID>0</OBJ_ID>
            <TREE_LEVEL>0</TREE_LEVEL>
            <OBJ_NAME>Templates</OBJ_NAME>
            <PARENT_ID>-1</PARENT_ID>
            <OBJ_TYPE>D</OBJ_TYPE>
        </DIR_OBJECT>
        <DIR_OBJECT>
            <ABSOLUTE_PATH>/home/pavel/Templates/test.txt</ABSOLUTE_PATH>
            <OBJ_ID>1</OBJ_ID>
            <TREE_LEVEL>1</TREE_LEVEL>
            <OBJ_NAME>test.txt</OBJ_NAME>
            <PARENT_ID>0</PARENT_ID>
            <OBJ_TYPE>F</OBJ_TYPE>
        </DIR_OBJECT>
    </dirObjects>
    
    

    and if I run the select statement of the following

    with
    xml_result as (
    select xtab.ABSOLUTE_PATH  ABSOLUTE_PATH
         , xtab.OBJ_TYPE
         , to_number(xtab.PARENT_ID) PARENT_ID
         , xtab.OBJ_NAME
         , to_number(xtab.TREE_LEVEL) TREE_LEVEL
         , to_number(xtab.OBJ_ID) OBJ_ID
      from apex_collections c,
              XMLTable('/dirObjects/DIR_OBJECT' passing xmltype001
                COLUMNS ABSOLUTE_PATH PATH 'ABSOLUTE_PATH'
                      , OBJ_TYPE PATH 'OBJ_TYPE'
                      , PARENT_ID PATH 'PARENT_ID'
                      , OBJ_NAME PATH 'OBJ_NAME'
                      , TREE_LEVEL PATH 'TREE_LEVEL'
                      , OBJ_ID PATH 'OBJ_ID'
              ) xtab
    where c.collection_name = 'P9_DOREST_RESULTS'
    )
    select ABSOLUTE_PATH,OBJ_TYPE,PARENT_ID,OBJ_NAME,TREE_LEVEL,OBJ_ID
    from
    xml_result
    --start with PARENT_ID =-1 connect by prior OBJ_ID=PARENT_ID
    
    

    He returned these 2 files

    Result:

    ABSOLUTE_PATH Obj_type PARENT_ID OBJ_NAME TREE_LEVEL OBJ_ID
    / Home/Pavel/templatesD-1Templates00
    /Home/Pavel/templates/test.txtF0test.txt11

    but when I Uncomment the last row, it returns nothing.

    When I insert exactly the same values in a normal table that looks like this:

    Name of Type Null

    ------------- ---- --------------

    ABSOLUTE_PATH VARCHAR2 (4000)

    OBJ_TYPE VARCHAR2 (4000)

    PARENT_ID NUMBER

    OBJ_NAME VARCHAR2 (4000)

    NUMBER OF TREE_LEVEL

    OBJ_ID NUMBER

    After the statement select returns the same result as the previous

    SELECT ABSOLUTE_PATH ,OBJ_TYPE ,PARENT_ID ,OBJ_NAME ,TREE_LEVEL ,OBJ_ID
    FROM dir_objects
    --START WITH parent_id    =-1 CONNECT BY prior obj_id =parent_id
    
    

    Result:

    ABSOLUTE_PATH Obj_type PARENT_ID OBJ_NAME TREE_LEVEL OBJ_ID
    / Home/Pavel/templatesD-1Templates00
    /Home/Pavel/templates/test.txtF0test.txt11

    but when I Uncomment the last row (START WITH parent_id = - 1 CONNECT BY prior obj_id = parent_id), it always returns 2 records

    Result:

    ABSOLUTE_PATH Obj_type PARENT_ID OBJ_NAME TREE_LEVEL OBJ_ID
    / Home/Pavel/templatesD-1Templates00
    /Home/Pavel/templates/test.txtF0test.txt11

    Any idea what is the difference and why the first select statement returns no that anything would be much appreciated.

    Best regards

    Pavel

    The solution to this nasty bug and arresting the optimizer doing a rewrite buggy was to use a scalar subquery via dual and expose the XML in this way.

    Select ABSOLUTE_PATH, OBJ_TYPE,

    PARENT_ID, OBJ_NAME,

    TREE_LEVEL, OBJ_ID

    from (select xtab. ABSOLUTE_PATH ABSOLUTE_PATH,

    xtab. OBJ_TYPE,

    TO_NUMBER (xtab. PARENT_ID PARENT_ID),

    xtab. OBJ_NAME,

    TO_NUMBER (xtab. TREE_LEVEL TREE_LEVEL),

    TO_NUMBER (xtab. OBJ_ID OBJ_ID)

    from (select (select xmltype001

    of apex_collections c

    where c.collection_name = 'P9_DOREST_RESULTS') as xmltype001

    the double) c,.

    XMLTable)

    ' / dirObjects/DIR_OBJECT.

    passage xmltype001

    COLUMNS

    ABSOLUTE_PATH PATH "ABSOLUTE_PATH."

    OBJ_TYPE PATH "OBJ_TYPE."

    PARENT_ID PATH "PARENT_ID"

    OBJ_NAME PATH "OBJ_NAME,"

    TREE_LEVEL PATH "TREE_LEVEL."

    OBJ_ID PATH "OBJ_ID.

    ) xtab

    )

    Start by PARENT_ID = - 1

    Connect prior OBJ_ID = PARENT_ID

  • Geez, Fusion 5.0 looks like it is not ready for prime time!

    I rely on the merger to run my Sunos 10.5, 10.6, Windows 7, oS Linux RHE.   I don't have not upgraded to ML yet due to some issues with IPSEC VPN.  It seems now 5 Fusion does not work with Lion 10.7.4 and that's the least of his problems.  It is such a disaster that brought me from Parallels to VMWARE in 3.0, despite the fact that it turns out that they charge $50 every year or so for upgrades and I two MBP to upgrade.

    Interesting that this upgrade is timed with a deal to get the latest Parallels for $39, if you have VMware.  I used a trial version and imported a Solaris 10.5 UNIX, WIndows 7 and 10.4 Fedora Linux VM and works very well.  What the hell happened to FUsion?   Is this the type of press

    We can expect on the hypervisor pro?  Should I look for to start recommending open source hypervisor (which we all know well)?

    From the personal and professional point of view, I have some real serious concerns here.  I have a lot of clients running the VMWARE hypervisor for virtualization on Wall Street.  I think it just barely live Q / a.  Looks like I really need start looking for ZEN.  Irony is that the C-level execs seem like when a product is 'legitimated' by price, releases, etc. (so of Fedora and RHE, at the time not taken seriously until)

    RHE came out for $3,000... then it's OK).

    Looks like it's back to Parallels. + 2 parallels.   I can't take a chance of installing junk that don't work.

    V10.7.4 OS X has some issues with usb3 devices stability, as it seems. I saw it myself, and it has lot of problems mentioned by people on different forums. Mountain Lion seems to have a more stable usb3 pilot, even if there are still some problems. I have to admit that I see many problems with usb3 and stability in general (meaning: also on Windows 7). Maybe that usb3 for OS X and Windows 7 drivers may need time to mature. I hope it is different with Linux and Windows 8. Maybe it's the cause of your problems, but I'm not sure about this.

    Anyway, you mention that the external hard drive uses its own encryption and merge sort is not able to use the virtual disk to the virtual machine. You are able to use this external drive like any other drive in OS X? As creating folders, copying documents from the drive, removal of files, etc.. It worked with Fusion 4.1.3 on the same machine? How did you upgrade? Did you stop all the vm before the upgrade or you did suspend?

    Just for my own information: are you currently testdriving VMware Fusion 5?

    Edit: I was reading the notes version and found some thing usb3 in the known "problems":

    • Unable to start a VM from USB 3.0 on MacBook Air 5.1 devices
      You may not be able to start a virtual machine from the devices USB 3.0 on MacBook Air 5.1.
      When you attach a USB 3.0 device, you see the error messageThe  device 'XXX' was unable to connect to its ideal host controller. An  attempt will be made to connect this device to the available host  controller. This might result in undefined behavior for this device.

      You can ignore the error message and the installation of the OS on the USB device. However, after restarting the virtual machine, the USB 3.0 device does not appear in the Start Menu.

      Solution: Use a USB 2.0 as a replacement device.

    This sounds a bit like the problem you are experiencing. I wonder if it isn't just a problem of usb3 with all new MBA 2012 and MBP models (including the retina MBP). Maybe someone else can shed some light on this.

    Post edited by: treee. Usb3 added info to release notes

  • 'Pull out' text preset - looks like nothing seen - wasting my time?

    Hello

    I read here and on Creative Cow tips on the importance of stroke in the use of this preset.

    But still tweaking the strokes and the parameters predefined this effect seems to look very little like its preview in bridge.  It seems to be missing something that controls the more organic 'emerging' of each individual letter that can be seen by watching the preview more in detail.

    If I'm missing something that I'd love to hear on this subject - or perhaps I should just accept that the effect is not what it is cut and try to get there otherwise?  Any suggestions much appreciated!

    Thank you

    D

    Darryl: test I just realized, it seems that text animation preset will alone that like preview thumbnails in bridge, when the color of the outline is exactly the same as the background color (or if you have something underneath, the same color as this element). If you are compositing it directly on top of video sequences, for example, it won't look like as it does in the preview.

    So, if you have the color of black background or black graphic third lower (for example), set the color of the text to the black edge.

  • Make JavaFX alerts look like ControlsFX dialogue

    Hello

    is there a way to make the official dialogue boxes (alerts) 8u40 looks like ControlsFX dialog boxes?

    I am talking mainly about the black title bar and slightly "generic" gray (who appear to be white in alert javafx?) as seen here:

    http://controlsfx.BitBucket.org/org/controlsfx/dialog/dialogs.html

    Thank you

    ControlsFX dialog boxes are deprecated,

    See the following blog announcement:

    Announces ControlsFX 8.20.7 / / JavaFX News, demos and Insight / / FX experience

    Use rather openjfx-dialog boxes:

    https://BitBucket.org/controlsfx/openjfx-dialogs

    This project is the controlsfx dialog box (probably the style you want), the features implemented on top of the new API of the Java 8u40 dialog box.

    Dialogs in the basic platform do not natively have the ability to return at your leisure without improvements that (I assume) are in openjfx-dialogues.

    ----

    I looked inside and I assumed wrong, openjfx-dialogue just seems to be a copy of the Java8u40 API dialog box so it has all the features of the obsolete ControlsFX dialog boxes.

    I guess your best bet to get the dialog boxes works the way you want is to use the deprecated ControlsFX API dialog box.

    Directly contact the developers of ControlsFX if you have any other questions.

    https://groups.Google.com/Forum/?hl=en#! controlsfx/forum-dev

    I see the currently last post is titled 'The plan for the dialogues'... it reads:

    (4) the existing dialogs API in ControlsFX will be deprecated but not

    deleted. This API will be removed when we planned on JavaFX 8u40. If

    you use the ControlsFX dialog boxes, please take the time to transition away from

    the old API as soon as possible. If there are things that you could do once

    Now you can't, please file bugs, but please note that we will not

    bring all the features (for example I'm sorry to say that I won't be

    bring back the light dialog boxes unless someone puts a big bag of

    money).

  • Firefox 4 sucks big time. I uninstalled and downloaded 3.6.17.

    Sorry, Mozilla, but Firefox 4 sucks big time. I uninstalled and downloaded 3.6.17. I have disabled the automatic updates. V4 breaks JQuery and who knows what else, so I'll be a customer throughout my version of v3.6.17, coz I'm simply not having established, clean, great code killed by the browser! Only, I'm building web apps, so I have to get all my clients to stop the upgrade, too. I've been a Firefox guy for years, but it's the end of my rope. Chrome is very good, as is Safari. I guess one of them is going to be my browser go forward.

    Thank you all. I'm back, with my clients to the latest version of Firefox and have ruled on issues of JQuery. Firefox still rocks! Except maybe this logo that looks like a bowling ball, breaking a poor little Fox.

  • Reflow project look like my psd file? But why?

    Hello

    I try to use Adobe reflow for my client based on the desktop version of prototyp look a quick.

    I also appointed different levels such as bgd.jpg or logo.png but if I open / import a psd file in reflow it

    doesn't look like my psd design, I did.

    I'm sure there are things I need to know for example only max two level group folders

    in photoshop, not possible to hide, etc.

    Where can I find these details because in the other sense reflow is not to help me, but it's a shame

    I think that the potential is great for this application.

    I hope someone can help me and answer my question!

    Best regards

    Mark

    PS: of course, I had a look at the example of psd file that reflow offers in his training...

    My trick is giving on the reflow. I tried to use it for 2 years now and I always end up giving up. It has more bugs that anyone here will agree never to. The workflow is not well documented which led to days of lost time. Many attempts over the years, I managed to make a prototype that was actually 'almost' as if I had intended. The irony is that I don't understand even how I did the job. I don't think a minute that it is an application ready to be published to anyone, unless you try to completely frustrate and alienate your customers.

    It is not yet clear what the application is supposed to be for. Prototyping? of course as long as I really don't like what comes out, you can even define your own grid correctly! How is it in this world of CSS I can't even create stylesheets in reflow? How is it that when I choose a color as a hexadecimal value, the software displays his counterpart RGB in the interface? Why the available Panel change its values depending on whether it is the first, fourth, or whatever time I click an object? Why did undo something that often destroys all your work with no way to go back? I could go on and. I clearly do not learn and every now and then I always return to reflow and tries to use it only to get frustrated beyond belief. There is clearly a huge gap in the market for a request of this kind, unfortunately this is not it. There are others but so far I have failed to find one that works correctly without a string of anomalies and the frustrating quirks. Also, I can't believe that paying for a full subscription to CC I'm still considering software also. Rant on.

  • Just bought ss12 but lag on video filters / render big time.

    I have been using adobe premierePro 6 / canopus edius 6 so far. I recently bought a kit for a canon 6 d, which included the ss12. So I was happy at the idea of another environment that I have heard so much. The thing is that my projects look like 30 GB (weddings, etc.) and im getting problems with DCs / gal / make it big time. I have used other programs on this pc so its nothing on pc specifications etc. Canon 6 d files are full HD, so they are great and I import them directly from the camera. Means that means ss12 is meant "light"?

    Lito 6 d

    Thanks for the reply with the details.

    At first, please let me you have confirm... given the same computer, do you want to say that a project (full content) can be done in Premiere CS6 cannot be done using the first 12 items?

    You wrote

    Rendering of images on the timeline with effects etc to properly preview on a 8 min project becomes like 10 minutes. If I do not I do not see the clip that I edited because it gets frozen (not just lag). Is this normal?

    Yes, may be normal for unreturned timeline. When the source media are imported, if the preset project is set properly, the present content timeline with no coloured line, indicating that you look the best possible overview of the reading of the content of the timeline in the monitor of editing area. But, once the changes start, then rendered timeline is necessary to obtain the best possible overview of what you see in the monitor area reading Edit. This interpretation of the chronology is particularly important when effects, transitions, titles and non-native formats are involved. When it comes to timeline render times, that will depend on what has been applied to the images... example, application of the video stabilizer can add minutes at a time, while the brightness could add only seconds. But the important issue here is that, even if you have a card NVIDIA CUDA, Premiere Elements cannot benefit at the time of rendering timeline or indeed anything else compared to first CS6.

    You wrote

    For the pc specs: win7 64 bit, i7, 12 GB of ram, 4 GB quadro.

    Your background, I guess that the i7 is quad-core. Can we assume that the NVIDIA Guadro driver version is up-to-date according to the manufacturer of the card? Premiere Elements can take advantage of CUDA like Premiere Pro cards. So, generalizing, any card of video/graphics card NVIDIA or ATI with a driver update version should work with Premiere Elements. Regardless of the version of the adapter driver, updates... except in the case of the first elements 10 NVIDIA GeForce number where is a roll of version of the driver (to may 2013) must have first items 10 to work.

    If you increase the RAM installed to 32 GB, think that any significant change in the first 12 items change in performance.

    On the other hand, do you have problems with an 8 minute 10 GB Timeline, zone Edit preview and export? If not, where is the cut for any problem in relation to the problems - 16 minutes 20 GB, 32 GB 40... ?

    The question

    Means that means ss12 is meant "light"?

    If 'light' is used in the context of the overview and Premiere Elements is 'lighter' CS6 first in what it can not take advantage of the first CS6 CUDA NVIDIA GPU - acceleration and Adobe Mercury Playback Engine to decrease the time of rendering of chronology.

    For anything else, I would need to see more data in your workflow for the rendering time performance and export quality and the time.

    RTA

Maybe you are looking for