Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oracle weblogic portal 9.2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-0870
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote malicious users to sniff the session.
Bea Systems Weblogic Portal 9.2
Bea Systems Weblogic Portal 10.0
Oracle Weblogic Portal 9.2
NA
CVE-2008-0868
Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.
Bea Systems Weblogic Portal 10.0
Oracle Weblogic Portal 9.2
NA
CVE-2007-2702
Cross-site scripting (XSS) vulnerability in the GroupSpace application in BEA WebLogic Portal 9.2 GA allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the rich text editor.
Oracle Weblogic Portal 9.2
NA
CVE-2007-2703
BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.
Oracle Weblogic Portal 9.2
NA
CVE-2007-0423
BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.
Oracle Weblogic Portal 9.2
NA
CVE-2007-0426
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allo...
Oracle Weblogic Portal 9.2
NA
CVE-2007-5576
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate malicious users to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
Bea Weblogic Server 8.1
Bea Weblogic Server 7.0
Bea Weblogic Server 7.0.0.1
Bea Weblogic Server 6.1
Bea Tuxedo 8.0
Bea Weblogic Integration 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 9.2
Bea Weblogic Workshop 8.1
Bea Weblogic Integration 9.2
Bea Weblogic Server 5.1
Bea Weblogic Server 9.1
Bea Tuxedo 8.1
Oracle Weblogic Portal 9.2
6.2
CVSSv3
CVE-2017-15707
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
Apache Struts
Netapp Oncommand Balance -
Oracle Weblogic Server 12.2.1.2
Oracle Jd Edwards Enterpriseone Tools 9.2
Oracle Retail Xstore Point Of Service 7.1.6
Oracle Retail Xstore Point Of Service 7.0.6
Oracle Retail Xstore Point Of Service 6.5.11
Oracle Retail Xstore Point Of Service 15.0.1
Oracle Financial Services Market Risk Measurement And Management 8.0.5
Oracle Webcenter Portal 12.2.1.3.0
Oracle Webcenter Portal 12.2.1.2.0
Oracle Weblogic Server 12.2.1.3
Oracle Retail Xstore Point Of Service 16.0.2
Oracle Retail Order Broker 5.2
Oracle Enterprise Manager For Virtualization 13.2.2
Oracle Enterprise Manager For Virtualization 13.2.3
Oracle Financial Services Hedge Management And Ifrs Valuations 8.0.4
Oracle Financial Services Hedge Management And Ifrs Valuations 8.0.5
Oracle Global Lifecycle Management Opatchauto
Oracle Agile Plm Framework 9.3.6
7.5
CVSSv3
CVE-2019-17359
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Bouncycastle Legion-of-the-bouncy-castle-java-crytography-api 1.63
Apache Tomee 7.0.7
Apache Tomee 7.1.2
Apache Tomee 8.0.1
Netapp Oncommand Workflow Automation -
Netapp Service Level Manager -
Netapp Oncommand Api Services -
Netapp Active Iq Unified Manager
Oracle Flexcube Private Banking 12.1.0
Oracle Flexcube Private Banking 12.0.0
Oracle Peoplesoft Enterprise Peopletools 8.56
Oracle Hospitality Guest Access 4.2.0
Oracle Weblogic Server 12.2.1.3.0
Oracle Webcenter Portal 12.2.1.3.0
Oracle Webcenter Portal 11.1.1.9.0
Oracle Business Process Management Suite 12.2.1.3.0
Oracle Soa Suite 12.2.1.3.0
Oracle Peoplesoft Enterprise Peopletools 8.57
Oracle Managed File Transfer 12.2.1.3.0
Oracle Retail Xstore Point Of Service 18.0.1
Oracle Weblogic Server 12.2.1.4.0
Oracle Peoplesoft Enterprise Peopletools 8.58
NA
CVE-2008-5462
Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote malicious users to affect confidentiality, integrity, and availability via unknown vectors.
Oracle Bea Product Suite 8.1
Oracle Bea Product Suite 10.0
Oracle Bea Product Suite 10.2
Oracle Bea Product Suite 10.3
Oracle Bea Product Suite 9.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »