Vulnerabilities > BEA > Weblogic Integration > High

DATE CVE VULNERABILITY TITLE RISK
2007-05-16 CVE-2007-2705 Directory Traversal vulnerability in BEA Weblogic Integration and Weblogic Workshop
Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Workshop 8.1 SP2 through SP6, when "deployed in an exploded format," allows remote attackers to list a WebLogic Workshop Directory (wlwdir) parent directory via unspecified vectors.
network
low complexity
bea
7.8
2002-12-31 CVE-2002-2142 Unspecified vulnerability in BEA Weblogic Integration and Weblogic Server
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.
network
low complexity
bea
7.5