NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61161 | CVE-2006-2466 | BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability." | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
52638 | CVE-2007-0411 | BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
52640 | CVE-2007-0413 | BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file. | 2 | 4.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
52642 | CVE-2007-0415 | BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
52635 | CVE-2007-0408 | BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View |
Page 16161 of 17672, showing 5 records out of 88360 total, starting on record 80801, ending on 80805