Bea

Weblogic Server

149 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 21.02.2008 01:44:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogi...

  • EPSS 0.6%
  • Published 18.10.2007 21:17:00
  • Last modified 09.04.2025 00:30:58

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls c...

  • EPSS 0.65%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the el...

  • EPSS 0.37%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

BEA WebLogic Server 9.1 does not properly handle propagation of an admin server's security policy change log to temporarily unavailable managed servers, which might allow attackers to bypass intended restrictions, a different vulnerability than CVE-2...

  • EPSS 0.72%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.

  • EPSS 0.86%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might ...

  • EPSS 1.55%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP4 allows remote attackers to cause a denial of service (server thread hang) via unspecified vectors.

  • EPSS 2.34%
  • Published 31.08.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.

  • EPSS 0.38%
  • Published 16.05.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0 GA, and 9.1 GA allow remote attackers to inject arbitrary web script or HTML via unspecified vector...

  • EPSS 2.04%
  • Published 16.05.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "external requests on behalf of a system identity," whic...