Vulnerability index

Browse CVEs

114 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weblogic Server MEDIUM 6.4
CVE-2010-2375EPSS 7%

Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware…

No fix yet
Fix from $1,600 2010-07-13
Weblogic Server HIGH 10.0
CVE-2008-3257EPSS 84%

Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote …

Fix: after 10.3
Fix from $1,950 2008-07-22
Weblogic Server HIGH 7.9
CVE-2008-0897

Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended …

Patch available
Fix from $1,950 2008-02-22
Weblogic Server HIGH 7.1
CVE-2008-0901

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout …

Patch available
Fix from $1,950 2008-02-22
Weblogic Server MEDIUM 6.4
CVE-2008-0895

BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted reque…

Patch available
Fix from $1,600 2008-02-22
Weblogic Server MEDIUM 6.0
CVE-2008-0900EPSS 10%

Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to…

Patch available
Fix from $1,600 2008-02-22
Weblogic Server MEDIUM 5.8
CVE-2008-0898

The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client canno…

Patch available
Fix from $1,600 2008-02-22
Weblogic Server MEDIUM 5.0
CVE-2008-0863

BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain se…

Patch available
Fix from $1,600 2008-02-21
Weblogic Mobility Server HIGH 7.5
CVE-2007-6384

Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attack…

Patch available
Fix from $1,950 2007-12-15
Aqualogic Interaction MEDIUM 5.0
CVE-2007-6197

The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal …

Patch available
Fix from $1,600 2007-12-01
Aqualogic Interaction MEDIUM 5.0
CVE-2007-6198EPSS 7%

portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for u…

Patch available
Fix from $1,600 2007-12-01
Tuxedo MEDIUM 6.8
CVE-2007-5576

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically p…

Mitigation only
Fix from $1,600 2007-10-18
Weblogic Server HIGH 7.8
CVE-2007-4617

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackers to caus…

Mitigation only
Fix from $1,950 2007-08-31
Weblogic Server HIGH 7.8
CVE-2007-4618

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (…

Patch available
Fix from $1,950 2007-08-31
Weblogic Server HIGH 7.5
CVE-2007-4614

BEA WebLogic Server 9.1 does not properly handle propagation of an admin server's security policy change log to temporarily unavailable managed serve…

Patch available
Fix from $1,950 2007-08-31
Weblogic Server MEDIUM 6.8
CVE-2007-4613

SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plai…

Patch available
Fix from $1,600 2007-08-31
Weblogic Server MEDIUM 6.4
CVE-2007-4615

The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the nul…

Fix: after 9.2
Fix from $1,600 2007-08-31
Weblogic Server MEDIUM 6.4
CVE-2007-4616

The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes s…

Patch available
Fix from $1,600 2007-08-31
Weblogic Integration HIGH 7.8
CVE-2007-2705

Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through SP6, when…

Patch available
Fix from $1,950 2007-05-16
Weblogic Server HIGH 7.1
CVE-2007-2699EPSS 29%

The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which …

Patch available
Fix from $1,950 2007-05-16
Weblogic Server MEDIUM 6.8
CVE-2007-2696

The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which…

Patch available
Fix from $1,600 2007-05-16
Weblogic Server MEDIUM 5.4
CVE-2007-2704

BEA WebLogic Server 9.0 through 9.2 allows remote attackers to cause a denial of service (SSL port unavailability) by accessing a half-closed SSL soc…

Patch available
Fix from $1,600 2007-05-16
Weblogic Server MEDIUM 5.1
CVE-2007-2695

The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9…

Patch available
Fix from $1,600 2007-05-16
Weblogic Server MEDIUM 5.1
CVE-2007-2697

The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, …

Patch available
Fix from $1,600 2007-05-16
Weblogic Server MEDIUM 5.0
CVE-2007-2698

The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration creation, which allows remote at…

Patch available
Fix from $1,600 2007-05-16
Aqualogic Service Bus HIGH 7.5
CVE-2007-0432

BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attacker…

No fix yet
Fix from $1,950 2007-01-23
Aqualogic Service Bus MEDIUM 6.5
CVE-2007-0433

Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP fo…

Mitigation only
Fix from $1,600 2007-01-23
Weblogic Server HIGH 10.0
CVE-2007-0417

BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers …

Fix: after 7.0
Fix from $1,950 2007-01-23
Weblogic Server HIGH 7.5
CVE-2007-0408

BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers…

Fix: after 8.1
Fix from $1,950 2007-01-23
Weblogic Server HIGH 7.5
CVE-2007-0416

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows r…

Patch available
Fix from $1,950 2007-01-23