NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70354  CVE-2005-4765  BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.    7.6  High  2017-01-03  2008-09-05  View
70349  CVE-2005-4760  BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."    5.1  Medium  2017-01-03  2008-09-05  View
70346  CVE-2005-4757  BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.    7.5  High  2017-01-03  2008-09-05  View
70343  CVE-2005-4754  BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation."    Medium  2017-01-03  2008-09-05  View
70344  CVE-2005-4755  BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key passphrase in cleartext (2) on a terminal or (3) in a log file, which might allow local users to obtain cryptographic keys.    2.1  Low  2017-01-03  2008-09-05  View

Page 16155 of 17672, showing 5 records out of 88360 total, starting on record 80771, ending on 80775

Actions