NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67468 | CVE-2005-1744 | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
71079 | CVE-2004-0652 | BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
74360 | CVE-2003-1290 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI). | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
73073 | CVE-2004-2696 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call. | 2 | 5.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
865 | CVE-2008-0895 | BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers. | 2 | 6.4 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 16157 of 17672, showing 5 records out of 88360 total, starting on record 80781, ending on 80785