İçeriğe atla
Noroxi

bea kayıtları

bea üreticisine ait 159 yayımlanmış kayıt.

Tüm kayıtlar

159 kayıt
  • CVE-2008-3257
    65Bu hafta

    Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allow

    KritikCVSS 10,0SilahlaştırılmışEPSS %84

    bea · weblogic server22 Tem 2008

  • CVE-2001-0098
    64Bu hafta

    Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a

    KritikCVSS 10,0Kavram kanıtıEPSS %78

    bea · weblogic server12 Şub 2001

  • CVE-2000-0681
    55Planlayın

    Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensi

    KritikCVSS 10,0İstismar yokEPSS %51

    bea · weblogic server20 Eki 2000

  • CVE-2004-0204
    52Planlayın

    Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used

    YüksekCVSS 7,5Kavram kanıtıEPSS %72

    bea · weblogic server6 Ağu 2004

  • CVE-2000-0685
    44Planlayın

    BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Ja

    KritikCVSS 10,0Kavram kanıtıEPSS %12

    bea · weblogic server20 Eki 2000

  • CVE-2000-0684
    44Planlayın

    BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP c

    KritikCVSS 10,0Kavram kanıtıEPSS %12

    bea · weblogic server20 Eki 2000

  • CVE-2003-0640
    41Planlayın

    BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and

    KritikCVSS 10,0İstismar yokEPSS %2

    bea · weblogic server27 Ağu 2003

  • CVE-2007-0417
    41Planlayın

    BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows a

    KritikCVSS 10,0İstismar yokEPSS %2

    bea · weblogic server22 Oca 2007

  • CVE-2005-1744
    40Planlayın

    BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t

    KritikCVSS 9,8İstismar yokEPSS %2

    bea · weblogic server24 May 2005

  • CVE-2007-2699
    37İzleyin

    The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policie

    YüksekCVSS 7,1İstismar yokEPSS %29

    bea · weblogic server15 May 2007

  • CVE-2007-4618
    32İzleyin

    Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of

    YüksekCVSS 7,8İstismar yokEPSS %2

    bea · weblogic server30 Ağu 2007

  • CVE-2007-4617
    32İzleyin

    Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attacker

    YüksekCVSS 7,8İstismar yokEPSS %2

    bea · weblogic server30 Ağu 2007

  • CVE-2007-2705
    32İzleyin

    Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through

    YüksekCVSS 7,8İstismar yokEPSS %2

    bea · weblogic integration15 May 2007

  • CVE-2003-0151
    31İzleyin

    BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative f

    YüksekCVSS 7,5İstismar yokEPSS %4

    bea · weblogic server24 Mar 2003

  • CVE-2000-1238
    31İzleyin

    BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet

    YüksekCVSS 7,5İstismar yokEPSS %3

    bea · weblogic server31 Ara 2000

  • CVE-2004-0470
    31İzleyin

    BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securi

    YüksekCVSS 7,5İstismar yokEPSS %3

    bea · weblogic server7 Tem 2004

  • CVE-2000-0499
    31İzleyin

    The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a

    YüksekCVSS 7,5İstismar yokEPSS %3

    bea · weblogic server8 Haz 2000

  • CVE-2002-2141
    31İzleyin

    BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove t

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server31 Ara 2002

  • CVE-2005-1743
    31İzleyin

    BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server24 May 2005

  • CVE-2005-4765
    31İzleyin

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 p

    YüksekCVSS 7,6İstismar yokEPSS %2

    bea · weblogic server31 Ara 2005

  • CVE-2005-4757
    31İzleyin

    BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roo

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server31 Ara 2005

  • CVE-2006-0426
    31İzleyin

    BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the ol

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server25 Oca 2006

  • CVE-2004-0711
    31İzleyin

    The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server27 Tem 2004

  • CVE-2006-2470
    31İzleyin

    Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server19 May 2006

  • CVE-2005-4756
    31İzleyin

    BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with mult

    YüksekCVSS 7,5İstismar yokEPSS %2

    bea · weblogic server31 Ara 2005