NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54867  CVE-2007-2703  BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.    3.6  Low  2017-01-07  2011-03-07  View
52650  CVE-2007-0423  BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.    4.4  Medium  2017-01-07  2011-03-07  View
59163  CVE-2006-0425  BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.    Medium  2016-12-20  2011-03-07  View
59161  CVE-2006-0423  BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.    7.5  High  2016-12-20  2011-03-07  View
866  CVE-2008-0896  BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.    4.9  Medium  2017-01-03  2011-03-07  View

Page 16164 of 17672, showing 5 records out of 88360 total, starting on record 80816, ending on 80820

Actions