NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
841  CVE-2008-0870  BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.    7.5  High  2017-01-03  2011-03-07  View
74507  CVE-2003-1437  BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.    2.1  Low  2017-01-03  2008-09-05  View
74292  CVE-2003-1222  BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.    Medium  2017-01-03  2008-09-10  View
74291  CVE-2003-1221  BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.    Medium  2017-01-03  2008-09-10  View
52636  CVE-2007-0409  BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.    1.5  Low  2017-01-07  2011-03-07  View

Page 16165 of 17672, showing 5 records out of 88360 total, starting on record 80821, ending on 80825

Actions