Show filters
140 Total Results
Displaying 61-70 of 140
Sort by:
Attacker Value
Unknown

CVE-2007-0415

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2007-0418

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.
0
Attacker Value
Unknown

CVE-2007-0412

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.
0
Attacker Value
Unknown

CVE-2007-0425

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.
0
Attacker Value
Unknown

CVE-2007-0414

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.
0
Attacker Value
Unknown

CVE-2007-0411

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.
0
Attacker Value
Unknown

CVE-2007-0417

Disclosure Date: January 23, 2007 (last updated October 04, 2023)
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.
0
Attacker Value
Unknown

CVE-2006-2546

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2006-2461

Disclosure Date: May 19, 2006 (last updated October 04, 2023)
BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic.
0
Attacker Value
Unknown

CVE-2006-2469

Disclosure Date: May 19, 2006 (last updated October 04, 2023)
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.
0