Show filters
118 Total Results
Displaying 41-50 of 118
Sort by:
Attacker Value
Unknown

CVE-2007-2697

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication attempts, which allows remote attackers to more easily conduct brute-force attacks against the administrator password, or flood the server with login attempts and cause a denial of service.
0
Attacker Value
Unknown

CVE-2007-0410

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events."
0
Attacker Value
Unknown

CVE-2007-0409

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
0
Attacker Value
Unknown

CVE-2007-0418

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.
0
Attacker Value
Unknown

CVE-2007-0412

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.
0
Attacker Value
Unknown

CVE-2007-0414

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.
0
Attacker Value
Unknown

CVE-2007-0421

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.
0
Attacker Value
Unknown

CVE-2007-0417

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.
0
Attacker Value
Unknown

CVE-2006-2469

Disclosure Date: May 19, 2006 (last updated October 04, 2023)
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2006-2462

Disclosure Date: May 19, 2006 (last updated October 04, 2023)
BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic.
0