NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79122  CVE-2002-0106  BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.    Medium  2017-01-05  2016-10-17  View
77470  CVE-2000-1238  BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.    7.5  High  2017-07-18  2017-07-10  View
67801  CVE-2005-2092  BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."    4.3  Medium  2017-07-18  2017-07-10  View
52659  CVE-2007-0432  BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.    7.5  High  2017-01-07  2008-11-13  View
52661  CVE-2007-0434  BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.    4.6  Medium  2017-01-07  2008-11-13  View

Page 16167 of 17672, showing 5 records out of 88360 total, starting on record 80831, ending on 80835

Actions