NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
866 | CVE-2008-0896 | BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions. | 2 | 4.9 | Medium | 2017-01-03 | 2011-03-07 | View | |
867 | CVE-2008-0897 | Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions. | 2 | 7.9 | High | 2017-01-03 | 2011-03-07 | View | |
868 | CVE-2008-0898 | The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues. | 2 | 5.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
869 | CVE-2008-0899 | Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
870 | CVE-2008-0900 | Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors. | 2 | 6 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 174 of 17672, showing 5 records out of 88360 total, starting on record 866, ending on 870