Vulnerability index

Browse CVEs

114 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weblogic Server HIGH 7.5
CVE-2005-4763

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) i…

Mitigation only
Fix from $1,950 2005-12-31
Weblogic Server HIGH 7.2
CVE-2005-4762

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier sometimes stores the boot password in the …

Patch available
Fix from $1,950 2005-12-31
Weblogic Server MEDIUM 6.8
CVE-2005-4751

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.4
CVE-2005-4766

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote att…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.1
CVE-2005-4760

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, doe…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.1
CVE-2005-4767

BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4704

Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to …

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4705

BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connect…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4749

HTTP request smuggling vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier al…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4753

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, in certain "heavy usage" scenarios, report incorrect severity …

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4754

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unkno…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server MEDIUM 5.0
CVE-2005-4759

BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about…

Patch available
Fix from $1,600 2005-12-31
Weblogic Server CRITICAL 9.8
CVE-2005-1744

BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those user…

Fix: after 7.0
Fix from $2,300 2005-05-24
Weblogic Server HIGH 7.5
CVE-2005-1743

BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider …

Mitigation only
Fix from $1,950 2005-05-24
Weblogic Server MEDIUM 6.8
CVE-2005-1747EPSS 5%

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, al…

Mitigation only
Fix from $1,600 2005-05-24
Weblogic Server MEDIUM 5.0
CVE-2005-1742

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

Mitigation only
Fix from $1,600 2005-05-24
Weblogic Server MEDIUM 5.0
CVE-2005-1746

The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even wh…

Mitigation only
Fix from $1,600 2005-05-24
Weblogic Server MEDIUM 5.0
CVE-2005-1748

The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds…

Mitigation only
Fix from $1,600 2005-05-24
Weblogic Server MEDIUM 5.0
CVE-2005-1749

Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption …

Mitigation only
Fix from $1,600 2005-05-24
Weblogic Server MEDIUM 6.8
CVE-2005-1380

Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server para…

No fix yet
Fix from $1,600 2005-05-03
Weblogic Server MEDIUM 5.0
CVE-2005-0432

BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an auth…

Patch available
Fix from $1,600 2005-05-02
Weblogic Server MEDIUM 5.5
CVE-2004-2696

BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does n…

Mitigation only
Fix from $1,600 2004-12-31
Weblogic Server MEDIUM 5.3
CVE-2004-2320

The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds…

Patch available
Fix from $1,600 2004-12-31
Weblogic Server MEDIUM 5.0
CVE-2004-2424

BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unkno…

Patch available
Fix from $1,600 2004-12-31
Weblogic Server HIGH 7.5
CVE-2004-0204EPSS 73%

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual…

Patch available
Fix from $1,950 2004-08-06
Weblogic Server HIGH 7.2
CVE-2004-0652

BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username …

Patch available
Fix from $1,950 2004-08-06
Weblogic Server HIGH 7.5
CVE-2004-0711

The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" patter…

Patch available
Fix from $1,950 2004-07-27
Weblogic Server MEDIUM 6.4
CVE-2004-0713

The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6…

Patch available
Fix from $1,600 2004-07-27
Weblogic Server MEDIUM 5.1
CVE-2004-0715

The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member …

Patch available
Fix from $1,600 2004-07-27
Weblogic Server HIGH 7.5
CVE-2004-0470

BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAss…

Patch available
Fix from $1,950 2004-07-07