Skip to content
Noroxi

bea records

159 published records for vendor bea.

All records

159 records
  • CVE-2008-3257
    65This week

    Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allow

    CriticalCVSS 10.0WeaponizedEPSS 84%

    bea · weblogic serverJul 22, 2008

  • CVE-2001-0098
    64This week

    Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a

    CriticalCVSS 10.0Proof of conceptEPSS 78%

    bea · weblogic serverFeb 12, 2001

  • Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensi

    CriticalCVSS 10.0No exploitEPSS 51%

    bea · weblogic serverOct 20, 2000

  • Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used

    HighCVSS 7.5Proof of conceptEPSS 72%

    bea · weblogic serverAug 6, 2004

  • BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Ja

    CriticalCVSS 10.0Proof of conceptEPSS 12%

    bea · weblogic serverOct 20, 2000

  • BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP c

    CriticalCVSS 10.0Proof of conceptEPSS 12%

    bea · weblogic serverOct 20, 2000

  • BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and

    CriticalCVSS 10.0No exploitEPSS 2%

    bea · weblogic serverAug 27, 2003

  • BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows a

    CriticalCVSS 10.0No exploitEPSS 2%

    bea · weblogic serverJan 22, 2007

  • BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t

    CriticalCVSS 9.8No exploitEPSS 2%

    bea · weblogic serverMay 24, 2005

  • CVE-2007-2699
    37Monitor

    The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policie

    HighCVSS 7.1No exploitEPSS 29%

    bea · weblogic serverMay 15, 2007

  • CVE-2007-4618
    32Monitor

    Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of

    HighCVSS 7.8No exploitEPSS 2%

    bea · weblogic serverAug 30, 2007

  • CVE-2007-4617
    32Monitor

    Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attacker

    HighCVSS 7.8No exploitEPSS 2%

    bea · weblogic serverAug 30, 2007

  • CVE-2007-2705
    32Monitor

    Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through

    HighCVSS 7.8No exploitEPSS 2%

    bea · weblogic integrationMay 15, 2007

  • CVE-2003-0151
    31Monitor

    BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative f

    HighCVSS 7.5No exploitEPSS 4%

    bea · weblogic serverMar 24, 2003

  • CVE-2000-1238
    31Monitor

    BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet

    HighCVSS 7.5No exploitEPSS 3%

    bea · weblogic serverDec 31, 2000

  • CVE-2004-0470
    31Monitor

    BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securi

    HighCVSS 7.5No exploitEPSS 3%

    bea · weblogic serverJul 7, 2004

  • CVE-2000-0499
    31Monitor

    The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a

    HighCVSS 7.5No exploitEPSS 3%

    bea · weblogic serverJun 8, 2000

  • CVE-2002-2141
    31Monitor

    BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove t

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverDec 31, 2002

  • CVE-2005-1743
    31Monitor

    BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverMay 24, 2005

  • CVE-2005-4765
    31Monitor

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 p

    HighCVSS 7.6No exploitEPSS 2%

    bea · weblogic serverDec 31, 2005

  • CVE-2005-4757
    31Monitor

    BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roo

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverDec 31, 2005

  • CVE-2006-0426
    31Monitor

    BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the ol

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverJan 25, 2006

  • CVE-2004-0711
    31Monitor

    The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverJul 27, 2004

  • CVE-2006-2470
    31Monitor

    Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverMay 19, 2006

  • CVE-2005-4756
    31Monitor

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with mult

    HighCVSS 7.5No exploitEPSS 2%

    bea · weblogic serverDec 31, 2005