NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
54867 | CVE-2007-2703 | BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources. | 2 | 3.6 | Low | 2017-01-07 | 2011-03-07 | View | |
52650 | CVE-2007-0423 | BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact. | 2 | 4.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
59163 | CVE-2006-0425 | BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59161 | CVE-2006-0423 | BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
866 | CVE-2008-0896 | BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions. | 2 | 4.9 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 16164 of 17672, showing 5 records out of 88360 total, starting on record 80816, ending on 80820