bea records
159 published records for vendor bea.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.6%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-287 Improper Authentication2
- CWE-399 Resource Management Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
159 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
65This week | CVE-2008-3257Weaponized | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allowbea · weblogic server · CWE-119 | Critical10.0 | — | 83.6% | Jul 22, 2008 |
64This week | CVE-2001-0098Proof of concept | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a bea · weblogic server | Critical10.0 | — | 78.4% | Feb 12, 2001 |
55Plan | CVE-2000-0681No exploit | Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensibea · weblogic server | Critical10.0 | — | 50.9% | Oct 20, 2000 |
52Plan | CVE-2004-0204Proof of concept | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | High7.5 | — | 72.4% | Aug 6, 2004 |
44Plan | CVE-2000-0685Proof of concept | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Jabea · weblogic server | Critical10.0 | — | 12.3% | Oct 20, 2000 |
44Plan | CVE-2000-0684Proof of concept | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP cbea · weblogic server | Critical10.0 | — | 12.3% | Oct 20, 2000 |
41Plan | CVE-2003-0640No exploit | BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames andbea · weblogic server | Critical10.0 | — | 2.0% | Aug 27, 2003 |
41Plan | CVE-2007-0417No exploit | BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows abea · weblogic server | Critical10.0 | — | 1.8% | Jan 22, 2007 |
40Plan | CVE-2005-1744No exploit | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Critical9.8 | — | 2.1% | May 24, 2005 |
37Monitor | CVE-2007-2699No exploit | The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policiebea · weblogic server | High7.1 | — | 29.3% | May 15, 2007 |
32Monitor | CVE-2007-4618No exploit | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of bea · weblogic server · CWE-399 | High7.8 | — | 2.5% | Aug 30, 2007 |
32Monitor | CVE-2007-4617No exploit | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackerbea · weblogic server · CWE-399 | High7.8 | — | 2.3% | Aug 30, 2007 |
32Monitor | CVE-2007-2705No exploit | Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through bea · weblogic integration | High7.8 | — | 1.7% | May 15, 2007 |
31Monitor | CVE-2003-0151No exploit | BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative fbea · weblogic server | High7.5 | — | 3.9% | Mar 24, 2003 |
31Monitor | CVE-2000-1238No exploit | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servletbea · weblogic server | High7.5 | — | 2.7% | Dec 31, 2000 |
31Monitor | CVE-2004-0470No exploit | BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securibea · weblogic server | High7.5 | — | 2.7% | Jul 7, 2004 |
31Monitor | CVE-2000-0499No exploit | The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a bea · weblogic server · CWE-178 | High7.5 | — | 2.5% | Jun 8, 2000 |
31Monitor | CVE-2002-2141No exploit | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove tbea · weblogic server | High7.5 | — | 2.4% | Dec 31, 2002 |
31Monitor | CVE-2005-1743No exploit | BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security bea · weblogic server | High7.5 | — | 2.2% | May 24, 2005 |
31Monitor | CVE-2005-4765No exploit | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 pbea · weblogic server | High7.6 | — | 2.1% | Dec 31, 2005 |
31Monitor | CVE-2005-4757No exploit | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roobea · weblogic server | High7.5 | — | 2.1% | Dec 31, 2005 |
31Monitor | CVE-2006-0426No exploit | BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the olbea · weblogic server | High7.5 | — | 2.0% | Jan 25, 2006 |
31Monitor | CVE-2004-0711No exploit | The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/bea · weblogic server | High7.5 | — | 1.9% | Jul 27, 2004 |
31Monitor | CVE-2006-2470No exploit | Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custombea · weblogic server | High7.5 | — | 1.8% | May 19, 2006 |
31Monitor | CVE-2005-4756No exploit | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multbea · weblogic server | High7.5 | — | 1.8% | Dec 31, 2005 |
- CVE-2008-325765This week
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allow
CriticalCVSS 10.0WeaponizedEPSS 84%bea · weblogic serverJul 22, 2008
- CVE-2001-009864This week
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a
CriticalCVSS 10.0Proof of conceptEPSS 78%bea · weblogic serverFeb 12, 2001
- CVE-2000-068155Plan
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensi
CriticalCVSS 10.0No exploitEPSS 51%bea · weblogic serverOct 20, 2000
- CVE-2004-020452Plan
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
HighCVSS 7.5Proof of conceptEPSS 72%bea · weblogic serverAug 6, 2004
- CVE-2000-068544Plan
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Ja
CriticalCVSS 10.0Proof of conceptEPSS 12%bea · weblogic serverOct 20, 2000
- CVE-2000-068444Plan
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP c
CriticalCVSS 10.0Proof of conceptEPSS 12%bea · weblogic serverOct 20, 2000
- CVE-2003-064041Plan
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and
CriticalCVSS 10.0No exploitEPSS 2%bea · weblogic serverAug 27, 2003
- CVE-2007-041741Plan
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows a
CriticalCVSS 10.0No exploitEPSS 2%bea · weblogic serverJan 22, 2007
- CVE-2005-174440Plan
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
CriticalCVSS 9.8No exploitEPSS 2%bea · weblogic serverMay 24, 2005
- CVE-2007-269937Monitor
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policie
HighCVSS 7.1No exploitEPSS 29%bea · weblogic serverMay 15, 2007
- CVE-2007-461832Monitor
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of
HighCVSS 7.8No exploitEPSS 2%bea · weblogic serverAug 30, 2007
- CVE-2007-461732Monitor
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attacker
HighCVSS 7.8No exploitEPSS 2%bea · weblogic serverAug 30, 2007
- CVE-2007-270532Monitor
Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through
HighCVSS 7.8No exploitEPSS 2%bea · weblogic integrationMay 15, 2007
- CVE-2003-015131Monitor
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative f
HighCVSS 7.5No exploitEPSS 4%bea · weblogic serverMar 24, 2003
- CVE-2000-123831Monitor
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet
HighCVSS 7.5No exploitEPSS 3%bea · weblogic serverDec 31, 2000
- CVE-2004-047031Monitor
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securi
HighCVSS 7.5No exploitEPSS 3%bea · weblogic serverJul 7, 2004
- CVE-2000-049931Monitor
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a
HighCVSS 7.5No exploitEPSS 3%bea · weblogic serverJun 8, 2000
- CVE-2002-214131Monitor
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove t
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverDec 31, 2002
- CVE-2005-174331Monitor
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverMay 24, 2005
- CVE-2005-476531Monitor
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 p
HighCVSS 7.6No exploitEPSS 2%bea · weblogic serverDec 31, 2005
- CVE-2005-475731Monitor
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roo
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverDec 31, 2005
- CVE-2006-042631Monitor
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the ol
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverJan 25, 2006
- CVE-2004-071131Monitor
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverJul 27, 2004
- CVE-2006-247031Monitor
Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverMay 19, 2006
- CVE-2005-475631Monitor
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with mult
HighCVSS 7.5No exploitEPSS 2%bea · weblogic serverDec 31, 2005