Show filters
118 Total Results
Displaying 91-100 of 118
Sort by:
Attacker Value
Unknown

CVE-2004-2696

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.
0
Attacker Value
Unknown

CVE-2004-1757

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2004-0652

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
0
Attacker Value
Unknown

CVE-2004-0715

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.
0
Attacker Value
Unknown

CVE-2004-0711

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.
0
Attacker Value
Unknown

CVE-2004-0713

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.
0
Attacker Value
Unknown

CVE-2004-0470

Disclosure Date: July 07, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.
0
Attacker Value
Unknown

CVE-2004-0471

Disclosure Date: July 07, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).
0
Attacker Value
Unknown

CVE-2004-1758

Disclosure Date: April 13, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2004-1756

Disclosure Date: April 13, 2004 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.
0