NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61161  CVE-2006-2466  BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability."    2.6  Low  2016-12-20  2011-03-07  View
52638  CVE-2007-0411  BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.    6.8  Medium  2017-01-07  2011-03-07  View
52640  CVE-2007-0413  BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.    4.4  Medium  2017-01-07  2011-03-07  View
52642  CVE-2007-0415  BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.    Medium  2017-01-07  2011-03-07  View
52635  CVE-2007-0408  BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.    7.5  High  2017-01-07  2011-03-07  View

Page 16161 of 17672, showing 5 records out of 88360 total, starting on record 80801, ending on 80805

Actions