NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67466 | CVE-2005-1742 | BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools." | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
72135 | CVE-2004-1756 | BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70348 | CVE-2005-4759 | BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently lose protection of Web Application pages. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
70906 | CVE-2004-0470 | BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70907 | CVE-2004-0471 | BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown). | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View |
Page 16156 of 17672, showing 5 records out of 88360 total, starting on record 80776, ending on 80780