Записи bea
159 опубликованных записей вендора bea.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,6 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-287 Improper Authentication2
- CWE-399 Resource Management Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
159 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
65На этой неделе | CVE-2008-3257Готовый эксплойт | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allowbea · weblogic server · CWE-119 | Критическая10,0 | — | 83,6 % | 22 июл. 2008 г. |
64На этой неделе | CVE-2001-0098Proof of concept | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a bea · weblogic server | Критическая10,0 | — | 78,4 % | 12 февр. 2001 г. |
55В плане | CVE-2000-0681Эксплойта нет | Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensibea · weblogic server | Критическая10,0 | — | 50,9 % | 20 окт. 2000 г. |
52В плане | CVE-2004-0204Proof of concept | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | Высокая7,5 | — | 72,4 % | 6 авг. 2004 г. |
44В плане | CVE-2000-0685Proof of concept | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Jabea · weblogic server | Критическая10,0 | — | 12,3 % | 20 окт. 2000 г. |
44В плане | CVE-2000-0684Proof of concept | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP cbea · weblogic server | Критическая10,0 | — | 12,3 % | 20 окт. 2000 г. |
41В плане | CVE-2003-0640Эксплойта нет | BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames andbea · weblogic server | Критическая10,0 | — | 2,0 % | 27 авг. 2003 г. |
41В плане | CVE-2007-0417Эксплойта нет | BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows abea · weblogic server | Критическая10,0 | — | 1,8 % | 22 янв. 2007 г. |
40В плане | CVE-2005-1744Эксплойта нет | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Критическая9,8 | — | 2,1 % | 24 мая 2005 г. |
37Наблюдать | CVE-2007-2699Эксплойта нет | The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policiebea · weblogic server | Высокая7,1 | — | 29,3 % | 15 мая 2007 г. |
32Наблюдать | CVE-2007-4618Эксплойта нет | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of bea · weblogic server · CWE-399 | Высокая7,8 | — | 2,5 % | 30 авг. 2007 г. |
32Наблюдать | CVE-2007-4617Эксплойта нет | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackerbea · weblogic server · CWE-399 | Высокая7,8 | — | 2,3 % | 30 авг. 2007 г. |
32Наблюдать | CVE-2007-2705Эксплойта нет | Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through bea · weblogic integration | Высокая7,8 | — | 1,7 % | 15 мая 2007 г. |
31Наблюдать | CVE-2003-0151Эксплойта нет | BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative fbea · weblogic server | Высокая7,5 | — | 3,9 % | 24 мар. 2003 г. |
31Наблюдать | CVE-2000-1238Эксплойта нет | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servletbea · weblogic server | Высокая7,5 | — | 2,7 % | 31 дек. 2000 г. |
31Наблюдать | CVE-2004-0470Эксплойта нет | BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securibea · weblogic server | Высокая7,5 | — | 2,7 % | 7 июл. 2004 г. |
31Наблюдать | CVE-2000-0499Эксплойта нет | The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a bea · weblogic server · CWE-178 | Высокая7,5 | — | 2,5 % | 8 июн. 2000 г. |
31Наблюдать | CVE-2002-2141Эксплойта нет | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove tbea · weblogic server | Высокая7,5 | — | 2,4 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2005-1743Эксплойта нет | BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security bea · weblogic server | Высокая7,5 | — | 2,2 % | 24 мая 2005 г. |
31Наблюдать | CVE-2005-4765Эксплойта нет | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 pbea · weblogic server | Высокая7,6 | — | 2,1 % | 31 дек. 2005 г. |
31Наблюдать | CVE-2005-4757Эксплойта нет | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roobea · weblogic server | Высокая7,5 | — | 2,1 % | 31 дек. 2005 г. |
31Наблюдать | CVE-2006-0426Эксплойта нет | BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the olbea · weblogic server | Высокая7,5 | — | 2,0 % | 25 янв. 2006 г. |
31Наблюдать | CVE-2004-0711Эксплойта нет | The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/bea · weblogic server | Высокая7,5 | — | 1,9 % | 27 июл. 2004 г. |
31Наблюдать | CVE-2006-2470Эксплойта нет | Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custombea · weblogic server | Высокая7,5 | — | 1,8 % | 19 мая 2006 г. |
31Наблюдать | CVE-2005-4756Эксплойта нет | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multbea · weblogic server | Высокая7,5 | — | 1,8 % | 31 дек. 2005 г. |
- CVE-2008-325765На этой неделе
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allow
КритическаяCVSS 10,0Готовый эксплойтEPSS 84 %bea · weblogic server22 июл. 2008 г.
- CVE-2001-009864На этой неделе
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a
КритическаяCVSS 10,0Proof of conceptEPSS 78 %bea · weblogic server12 февр. 2001 г.
- CVE-2000-068155В плане
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensi
КритическаяCVSS 10,0Эксплойта нетEPSS 51 %bea · weblogic server20 окт. 2000 г.
- CVE-2004-020452В плане
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
ВысокаяCVSS 7,5Proof of conceptEPSS 72 %bea · weblogic server6 авг. 2004 г.
- CVE-2000-068544В плане
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Ja
КритическаяCVSS 10,0Proof of conceptEPSS 12 %bea · weblogic server20 окт. 2000 г.
- CVE-2000-068444В плане
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP c
КритическаяCVSS 10,0Proof of conceptEPSS 12 %bea · weblogic server20 окт. 2000 г.
- CVE-2003-064041В плане
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %bea · weblogic server27 авг. 2003 г.
- CVE-2007-041741В плане
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows a
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %bea · weblogic server22 янв. 2007 г.
- CVE-2005-174440В плане
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bea · weblogic server24 мая 2005 г.
- CVE-2007-269937Наблюдать
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policie
ВысокаяCVSS 7,1Эксплойта нетEPSS 29 %bea · weblogic server15 мая 2007 г.
- CVE-2007-461832Наблюдать
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %bea · weblogic server30 авг. 2007 г.
- CVE-2007-461732Наблюдать
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attacker
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %bea · weblogic server30 авг. 2007 г.
- CVE-2007-270532Наблюдать
Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %bea · weblogic integration15 мая 2007 г.
- CVE-2003-015131Наблюдать
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative f
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %bea · weblogic server24 мар. 2003 г.
- CVE-2000-123831Наблюдать
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %bea · weblogic server31 дек. 2000 г.
- CVE-2004-047031Наблюдать
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %bea · weblogic server7 июл. 2004 г.
- CVE-2000-049931Наблюдать
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %bea · weblogic server8 июн. 2000 г.
- CVE-2002-214131Наблюдать
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server31 дек. 2002 г.
- CVE-2005-174331Наблюдать
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server24 мая 2005 г.
- CVE-2005-476531Наблюдать
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 p
ВысокаяCVSS 7,6Эксплойта нетEPSS 2 %bea · weblogic server31 дек. 2005 г.
- CVE-2005-475731Наблюдать
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roo
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server31 дек. 2005 г.
- CVE-2006-042631Наблюдать
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the ol
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server25 янв. 2006 г.
- CVE-2004-071131Наблюдать
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server27 июл. 2004 г.
- CVE-2006-247031Наблюдать
Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server19 мая 2006 г.
- CVE-2005-475631Наблюдать
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with mult
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bea · weblogic server31 дек. 2005 г.