Vulnerability index

Browse CVEs

114 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weblogic Server HIGH 7.5
CVE-2007-0418

BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB metho…

Fix: after 8.1
Fix from $1,950 2007-01-23
Jrockit HIGH 7.5
CVE-2007-0425

Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privi…

Fix: after 8.1
Fix from $1,950 2007-01-23
Weblogic Server MEDIUM 6.8
CVE-2007-0411

BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remo…

Fix: after 8.1
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 6.4
CVE-2007-0421

BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests…

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0410

Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is …

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0412

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the clas…

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0414

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (serv…

Fix: after 8.1
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0415

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application th…

Fix: after 8.1
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0419

The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attac…

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0420

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data fro…

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0422

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) …

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2007-0424

Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Serve…

Patch available
Fix from $1,600 2007-01-23
Weblogic Server MEDIUM 5.0
CVE-2006-2546

A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to…

Patch available
Fix from $1,600 2006-05-23
Weblogic Server HIGH 7.5
CVE-2006-2469

The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the We…

Patch available
Fix from $1,950 2006-05-19
Weblogic Server HIGH 7.5
CVE-2006-2470

Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC sec…

Patch available
Fix from $1,950 2006-05-19
Weblogic Server MEDIUM 5.0
CVE-2006-2461

BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmission…

Patch available
Fix from $1,600 2006-05-19
Weblogic Server MEDIUM 5.0
CVE-2006-2462

BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transact…

Patch available
Fix from $1,600 2006-05-19
Weblogic Server MEDIUM 5.0
CVE-2006-2471

Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers,…

Patch available
Fix from $1,600 2006-05-19
Weblogic Server MEDIUM 5.0
CVE-2006-1351

BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal ser…

Patch available
Fix from $1,600 2006-03-22
Weblogic Server MEDIUM 5.0
CVE-2006-1352

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to …

Patch available
Fix from $1,600 2006-03-22
Weblogic Server HIGH 7.5
CVE-2006-0426

BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new…

Patch available
Fix from $1,950 2006-01-25
Weblogic Server MEDIUM 6.4
CVE-2006-0419

BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows r…

Patch available
Fix from $1,600 2006-01-25
Weblogic Server MEDIUM 6.4
CVE-2006-0422

Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote a…

Patch available
Fix from $1,600 2006-01-25
Weblogic Server MEDIUM 5.0
CVE-2006-0420

BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which al…

Patch available
Fix from $1,600 2006-01-25
Weblogic Server MEDIUM 5.0
CVE-2006-0430

Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, ca…

Patch available
Fix from $1,600 2006-01-25
Weblogic Server HIGH 7.8
CVE-2005-4764

BEA WebLogic Server and WebLogic Express 9.0, 8.1, and 7.0 lock out the admin user account after multiple incorrect password guesses, which allows re…

Patch available
Fix from $1,950 2005-12-31
Weblogic Server HIGH 7.6
CVE-2005-4765

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, …

Patch available
Fix from $1,950 2005-12-31
Weblogic Server HIGH 7.5
CVE-2005-4750

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier allow remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2005-12-31
Weblogic Server HIGH 7.5
CVE-2005-4756

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple Prin…

Patch available
Fix from $1,950 2005-12-31
Weblogic Server HIGH 7.5
CVE-2005-4757

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pat…

Patch available
Fix from $1,950 2005-12-31