NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
841 | CVE-2008-0870 | BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
74507 | CVE-2003-1437 | BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
74292 | CVE-2003-1222 | BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password. | 2 | 5 | Medium | 2017-01-03 | 2008-09-10 | View | |
74291 | CVE-2003-1221 | BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions. | 2 | 5 | Medium | 2017-01-03 | 2008-09-10 | View | |
52636 | CVE-2007-0409 | BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password. | 2 | 1.5 | Low | 2017-01-07 | 2011-03-07 | View |
Page 16165 of 17672, showing 5 records out of 88360 total, starting on record 80821, ending on 80825