NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79122 | CVE-2002-0106 | BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
77470 | CVE-2000-1238 | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67801 | CVE-2005-2092 | BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
52659 | CVE-2007-0432 | BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
52661 | CVE-2007-0434 | BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection. | 2 | 4.6 | Medium | 2017-01-07 | 2008-11-13 | View |
Page 16167 of 17672, showing 5 records out of 88360 total, starting on record 80831, ending on 80835