Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bea weblogic server 9.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-0411
BEA WebLogic Server 8.1 up to and including 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote malicious users to conduct a man-in-the-middle (MITM) attack.
Bea Weblogic Server
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 9.1
Bea Weblogic Server 9.2
NA
CVE-2007-0414
BEA WebLogic Server 6.1 up to and including 6.1 SP7, 7.0 up to and including 7.0 SP6, 8.1 up to and including 8.1 SP5, and 9.0 allows remote malicious users to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pag...
Bea Weblogic Server
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 7.0
Bea Weblogic Server 6.1
NA
CVE-2007-0417
BEA WebLogic Server 7.0 up to and including 7.0 SP7, 8.1 up to and including 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows malicious users to execute certain EJB container persistence operations with an administrative identity.
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 7.0
Bea Weblogic Server 9.1
Bea Weblogic Server
NA
CVE-2007-0418
BEA WebLogic Server 7.0 up to and including 7.0 SP6, 8.1 up to and including 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote malicious users to obtain unauthorized access to these m...
Bea Weblogic Server
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 7.0
Bea Weblogic Server 9.1
NA
CVE-2007-4615
The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote malicious users to intercept communications.
Bea Weblogic Server 7.0
Bea Weblogic Server 9.0
Bea Weblogic Server 8.1
Bea Weblogic Server 9.1
Bea Weblogic Server 10.0
Bea Weblogic Server
NA
CVE-2007-0409
BEA WebLogic 7.0 up to and including 7.0 SP6, 8.1 up to and including 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 7.0
Bea Weblogic Server
NA
CVE-2007-4616
The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote malicious users t...
Bea Weblogic Server 7.0
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 9.2
Bea Weblogic Server 9.1
Bea Weblogic Server 10.0
NA
CVE-2008-0895
BEA WebLogic Server and WebLogic Express 6.1 up to and including 10.0 allows remote malicious users to bypass authentication for application servlets via crafted request headers.
Bea Weblogic Server 6.1
Bea Weblogic Server 7.0
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 9.2
Bea Weblogic Server 9.1
Bea Weblogic Server 10.0
NA
CVE-2006-2469
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows malicious users to gain privileges.
Bea Weblogic Server 6.1
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 7.0
Bea Weblogic Server 6.0
NA
CVE-2006-2472
Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys.
Bea Weblogic Server 8.1
Bea Weblogic Server 7.0
Bea Weblogic Server 6.1
Bea Weblogic Server 9.0
Bea Weblogic Server 9.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30078
CVE-2024-37896
code injection
CVE-2024-3080
CVE-2024-5172
cross-site request forgery
CVE-2024-6111
firmware
CVE-2024-38504
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »