Vulnerabilities > BEA > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-07-22 CVE-2008-3257 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
network
low complexity
bea bea-systems oracle CWE-119
critical
10.0
2007-01-23 CVE-2007-0417 Products Multiple vulnerability in BEA
BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.
network
low complexity
bea
critical
10.0
2005-05-24 CVE-2005-1744 Incomplete Cleanup vulnerability in BEA Weblogic Server
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
network
low complexity
bea CWE-459
critical
9.8
2003-08-27 CVE-2003-0640 Remote Security vulnerability in Weblogic Server
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
network
low complexity
bea
critical
10.0
2001-02-12 CVE-2001-0098 Buffer Overflow vulnerability in BEA Weblogic Server 4.5.2
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
network
low complexity
bea
critical
10.0
2000-10-20 CVE-2000-0685 Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
network
low complexity
bea
critical
10.0
2000-10-20 CVE-2000-0684 Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
network
low complexity
bea
critical
10.0
2000-10-20 CVE-2000-0681 Unspecified vulnerability in BEA Weblogic Server 4.5.2
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
network
low complexity
bea
critical
10.0