Show filters
140 Total Results
Displaying 91-100 of 140
Sort by:
Attacker Value
Unknown
CVE-2005-4752
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, might allow local users to gain privileges by using the run-as deployment descriptor element to change the privileges of a web application or EJB from the Deployer security role to the Admin security role.
0
Attacker Value
Unknown
CVE-2005-4766
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.
0
Attacker Value
Unknown
CVE-2005-4763
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) is used, sometimes include a password in an exception message that is sent to a client or stored in a log file, which might allow remote attackers to perform unauthorized actions.
0
Attacker Value
Unknown
CVE-2005-4705
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection.
0
Attacker Value
Unknown
CVE-2005-4755
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key passphrase in cleartext (2) on a terminal or (3) in a log file, which might allow local users to obtain cryptographic keys.
0
Attacker Value
Unknown
CVE-2005-4760
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."
0
Attacker Value
Unknown
CVE-2005-4751
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2005-4704
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2005-4759
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently lose protection of Web Application pages.
0
Attacker Value
Unknown
CVE-2005-4756
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple PrincipalValidators, which might allow attackers to gain privileges.
0