Show filters
140 Total Results
Displaying 101-110 of 140
Sort by:
Attacker Value
Unknown
CVE-2005-4767
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out a username after the maximum number of invalid login attempts, which makes it easier for remote attackers to guess the password.
0
Attacker Value
Unknown
CVE-2005-4757
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.
0
Attacker Value
Unknown
CVE-2005-4762
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier sometimes stores the boot password in the registry in cleartext, which might allow local users to gain administrative privileges.
0
Attacker Value
Unknown
CVE-2005-4750
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier allow remote attackers to cause a denial of service (server thread hang) via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2005-4761
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.
0
Attacker Value
Unknown
CVE-2005-4758
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed through HTTP.
0
Attacker Value
Unknown
CVE-2005-4765
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.
0
Attacker Value
Unknown
CVE-2005-2092
Disclosure Date: July 05, 2005 (last updated February 22, 2025)
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
0
Attacker Value
Unknown
CVE-2005-1747
Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.
0
Attacker Value
Unknown
CVE-2005-1746
Disclosure Date: May 24, 2005 (last updated February 22, 2025)
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.
0