NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61157 | CVE-2006-2462 | BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
52644 | CVE-2007-0417 | BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View | |
52645 | CVE-2007-0418 | BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
66190 | CVE-2005-0432 | BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
74165 | CVE-2003-1093 | BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16162 of 17672, showing 5 records out of 88360 total, starting on record 80806, ending on 80810