Vulnerabilities > BEA > Weblogic Server > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-07-22 | CVE-2008-3257 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. | 10.0 |
2007-01-23 | CVE-2007-0417 | Products Multiple vulnerability in BEA BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity. | 10.0 |
2005-05-24 | CVE-2005-1744 | Incomplete Cleanup vulnerability in BEA Weblogic Server BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings. | 9.8 |
2003-08-27 | CVE-2003-0640 | Remote Security vulnerability in Weblogic Server BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges. | 10.0 |
2001-02-12 | CVE-2001-0098 | Buffer Overflow vulnerability in BEA Weblogic Server 4.5.2 Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. | 10.0 |
2000-10-20 | CVE-2000-0681 | Unspecified vulnerability in BEA Weblogic Server 4.5.2 Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. | 10.0 |
2000-10-20 | CVE-2000-0684 | Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1 BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file. | 10.0 |
2000-10-20 | CVE-2000-0685 | Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1 BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file. | 10.0 |