bea kayıtları
bea üreticisine ait 159 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,6
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-287 Improper Authentication2
- CWE-399 Resource Management Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
159 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
65Bu hafta | CVE-2008-3257Silahlaştırılmış | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allowbea · weblogic server · CWE-119 | Kritik10,0 | — | %83,6 | 22 Tem 2008 |
64Bu hafta | CVE-2001-0098Kavram kanıtı | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a bea · weblogic server | Kritik10,0 | — | %78,4 | 12 Şub 2001 |
55Planlayın | CVE-2000-0681İstismar yok | Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensibea · weblogic server | Kritik10,0 | — | %50,9 | 20 Eki 2000 |
52Planlayın | CVE-2004-0204Kavram kanıtı | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used bea · weblogic server | Yüksek7,5 | — | %72,4 | 6 Ağu 2004 |
44Planlayın | CVE-2000-0685Kavram kanıtı | BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Jabea · weblogic server | Kritik10,0 | — | %12,3 | 20 Eki 2000 |
44Planlayın | CVE-2000-0684Kavram kanıtı | BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP cbea · weblogic server | Kritik10,0 | — | %12,3 | 20 Eki 2000 |
41Planlayın | CVE-2003-0640İstismar yok | BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames andbea · weblogic server | Kritik10,0 | — | %2,0 | 27 Ağu 2003 |
41Planlayın | CVE-2007-0417İstismar yok | BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows abea · weblogic server | Kritik10,0 | — | %1,8 | 22 Oca 2007 |
40Planlayın | CVE-2005-1744İstismar yok | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Kritik9,8 | — | %2,1 | 24 May 2005 |
37İzleyin | CVE-2007-2699İstismar yok | The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policiebea · weblogic server | Yüksek7,1 | — | %29,3 | 15 May 2007 |
32İzleyin | CVE-2007-4618İstismar yok | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of bea · weblogic server · CWE-399 | Yüksek7,8 | — | %2,5 | 30 Ağu 2007 |
32İzleyin | CVE-2007-4617İstismar yok | Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackerbea · weblogic server · CWE-399 | Yüksek7,8 | — | %2,3 | 30 Ağu 2007 |
32İzleyin | CVE-2007-2705İstismar yok | Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through bea · weblogic integration | Yüksek7,8 | — | %1,7 | 15 May 2007 |
31İzleyin | CVE-2003-0151İstismar yok | BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative fbea · weblogic server | Yüksek7,5 | — | %3,9 | 24 Mar 2003 |
31İzleyin | CVE-2000-1238İstismar yok | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servletbea · weblogic server | Yüksek7,5 | — | %2,7 | 31 Ara 2000 |
31İzleyin | CVE-2004-0470İstismar yok | BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securibea · weblogic server | Yüksek7,5 | — | %2,7 | 7 Tem 2004 |
31İzleyin | CVE-2000-0499İstismar yok | The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a bea · weblogic server · CWE-178 | Yüksek7,5 | — | %2,5 | 8 Haz 2000 |
31İzleyin | CVE-2002-2141İstismar yok | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove tbea · weblogic server | Yüksek7,5 | — | %2,4 | 31 Ara 2002 |
31İzleyin | CVE-2005-1743İstismar yok | BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security bea · weblogic server | Yüksek7,5 | — | %2,2 | 24 May 2005 |
31İzleyin | CVE-2005-4765İstismar yok | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 pbea · weblogic server | Yüksek7,6 | — | %2,1 | 31 Ara 2005 |
31İzleyin | CVE-2005-4757İstismar yok | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roobea · weblogic server | Yüksek7,5 | — | %2,1 | 31 Ara 2005 |
31İzleyin | CVE-2006-0426İstismar yok | BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the olbea · weblogic server | Yüksek7,5 | — | %2,0 | 25 Oca 2006 |
31İzleyin | CVE-2004-0711İstismar yok | The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/bea · weblogic server | Yüksek7,5 | — | %1,9 | 27 Tem 2004 |
31İzleyin | CVE-2006-2470İstismar yok | Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custombea · weblogic server | Yüksek7,5 | — | %1,8 | 19 May 2006 |
31İzleyin | CVE-2005-4756İstismar yok | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multbea · weblogic server | Yüksek7,5 | — | %1,8 | 31 Ara 2005 |
- CVE-2008-325765Bu hafta
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allow
KritikCVSS 10,0SilahlaştırılmışEPSS %84bea · weblogic server22 Tem 2008
- CVE-2001-009864Bu hafta
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a
KritikCVSS 10,0Kavram kanıtıEPSS %78bea · weblogic server12 Şub 2001
- CVE-2000-068155Planlayın
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extensi
KritikCVSS 10,0İstismar yokEPSS %51bea · weblogic server20 Eki 2000
- CVE-2004-020452Planlayın
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used
YüksekCVSS 7,5Kavram kanıtıEPSS %72bea · weblogic server6 Ağu 2004
- CVE-2000-068544Planlayın
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Ja
KritikCVSS 10,0Kavram kanıtıEPSS %12bea · weblogic server20 Eki 2000
- CVE-2000-068444Planlayın
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP c
KritikCVSS 10,0Kavram kanıtıEPSS %12bea · weblogic server20 Eki 2000
- CVE-2003-064041Planlayın
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and
KritikCVSS 10,0İstismar yokEPSS %2bea · weblogic server27 Ağu 2003
- CVE-2007-041741Planlayın
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows a
KritikCVSS 10,0İstismar yokEPSS %2bea · weblogic server22 Oca 2007
- CVE-2005-174440Planlayın
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
KritikCVSS 9,8İstismar yokEPSS %2bea · weblogic server24 May 2005
- CVE-2007-269937İzleyin
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policie
YüksekCVSS 7,1İstismar yokEPSS %29bea · weblogic server15 May 2007
- CVE-2007-461832İzleyin
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of
YüksekCVSS 7,8İstismar yokEPSS %2bea · weblogic server30 Ağu 2007
- CVE-2007-461732İzleyin
Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attacker
YüksekCVSS 7,8İstismar yokEPSS %2bea · weblogic server30 Ağu 2007
- CVE-2007-270532İzleyin
Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through
YüksekCVSS 7,8İstismar yokEPSS %2bea · weblogic integration15 May 2007
- CVE-2003-015131İzleyin
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative f
YüksekCVSS 7,5İstismar yokEPSS %4bea · weblogic server24 Mar 2003
- CVE-2000-123831İzleyin
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet
YüksekCVSS 7,5İstismar yokEPSS %3bea · weblogic server31 Ara 2000
- CVE-2004-047031İzleyin
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the Securi
YüksekCVSS 7,5İstismar yokEPSS %3bea · weblogic server7 Tem 2004
- CVE-2000-049931İzleyin
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a
YüksekCVSS 7,5İstismar yokEPSS %3bea · weblogic server8 Haz 2000
- CVE-2002-214131İzleyin
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove t
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server31 Ara 2002
- CVE-2005-174331İzleyin
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server24 May 2005
- CVE-2005-476531İzleyin
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 p
YüksekCVSS 7,6İstismar yokEPSS %2bea · weblogic server31 Ara 2005
- CVE-2005-475731İzleyin
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet roo
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server31 Ara 2005
- CVE-2006-042631İzleyin
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the ol
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server25 Oca 2006
- CVE-2004-071131İzleyin
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server27 Tem 2004
- CVE-2006-247031İzleyin
Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server19 May 2006
- CVE-2005-475631İzleyin
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with mult
YüksekCVSS 7,5İstismar yokEPSS %2bea · weblogic server31 Ara 2005