NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70343 | CVE-2005-4754 | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation." | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 70344 | CVE-2005-4755 | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key passphrase in cleartext (2) on a terminal or (3) in a log file, which might allow local users to obtain cryptographic keys. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
| 70345 | CVE-2005-4756 | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple PrincipalValidators, which might allow attackers to gain privileges. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 70346 | CVE-2005-4757 | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 70347 | CVE-2005-4758 | Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed through HTTP. | 2 | 4 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 3093 of 17672, showing 5 records out of 88360 total, starting on record 15461, ending on 15465