NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61157  CVE-2006-2462  BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic.    Medium  2016-12-20  2011-03-07  View
52644  CVE-2007-0417  BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.    10  High  2017-01-07  2011-03-07  View
52645  CVE-2007-0418  BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.    7.5  High  2017-01-07  2011-03-07  View
66190  CVE-2005-0432  BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.    Medium  2017-01-03  2008-09-05  View
74165  CVE-2003-1093  BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.    4.6  Medium  2017-07-18  2017-07-10  View

Page 16162 of 17672, showing 5 records out of 88360 total, starting on record 80806, ending on 80810

Actions