Vulnerabilities > BEA > Weblogic Server > 5.1

DATE CVE VULNERABILITY TITLE RISK
2007-01-23 CVE-2007-0408 Products Multiple vulnerability in BEA
BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.
network
low complexity
bea
7.5
2005-05-24 CVE-2005-1744 Incomplete Cleanup vulnerability in BEA Weblogic Server
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
network
low complexity
bea CWE-459
critical
9.8
2004-12-31 CVE-2004-2320 Information Exposure vulnerability in BEA Weblogic Server
The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
network
bea CWE-200
5.8
2003-12-31 CVE-2003-1438 Race Condition vulnerability in BEA Weblogic Server
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
network
bea CWE-362
4.3
2003-12-01 CVE-2003-0624 Cross-Site Scripting vulnerability in BEA Weblogic Server
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
network
bea CWE-79
4.3
2003-12-01 CVE-2003-0623 Unspecified vulnerability in BEA Tuxedo and Weblogic Server
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
network
bea
4.3
2003-12-01 CVE-2003-0622 Unspecified vulnerability in BEA Tuxedo and Weblogic Server
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.
network
low complexity
bea
5.0
2003-12-01 CVE-2003-0621 Unspecified vulnerability in BEA Tuxedo and Weblogic Server
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
network
low complexity
bea
5.0
2003-10-20 CVE-2003-0733 Cross-Site Scripting vulnerability in Bea WebLogic/Liquid Data
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console application.
network
bea
6.8
2002-10-04 CVE-2002-1030 Denial of Service vulnerability in BEA Systems WebLogic Server and Express Race Condition
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
network
high complexity
bea
2.6