Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bea weblogic server 8.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-0432
BEA WebLogic Server 7.0 Service Pack 5 and previous versions, and 8.1 Service Pack 3 and previous versions, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote malicious users to guess passwords via brute force a...
Bea Weblogic Server 8.1
Bea Weblogic Server 7.0
NA
CVE-2006-2462
BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote malicious users to read potentially sensitive network traffic.
Bea Weblogic Server 8.1
Bea Weblogic Server 7.0
NA
CVE-2004-1756
BEA WebLogic Server and WebLogic Express 8.1 SP2 and previous versions, and 7.0 SP4 and previous versions, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote malicious users to spoof other use...
Bea Weblogic Server 8.1
Bea Weblogic Server 7.0
NA
CVE-2008-3257
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and previous versions allows remote malicious users to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /....
Bea Weblogic Server 7.0.0.1
Bea Weblogic Server 6.1
Bea Weblogic Server 4.5.2
Bea Weblogic Server 4.5.1
Bea Weblogic Server 7.0
Bea Weblogic Server 9.2
Bea Weblogic Server 8.1
Bea Weblogic Server 9.0
Bea Weblogic Server 6.0
Bea Weblogic Server 5.1
Oracle Weblogic Server
Bea Weblogic Server 3.1.8
Bea Weblogic Server 4.5
Bea Weblogic Server 9.1
Bea Weblogic Server 10.0
Bea Systems Weblogic Server 10.0 Mp1
Bea Weblogic Server 4.0.4
Bea Systems Apache Connector In Weblogic Server
Bea Weblogic Server 4.0
2 EDB exploits
1 Github repository
NA
CVE-2003-0621
The Administration Console for BEA Tuxedo 8.1 and previous versions allows remote malicious users to determine the existence of files outside the web root via modified paths in the INIFILE argument.
Bea Tuxedo 8.0
Bea Tuxedo 7.1
Bea Weblogic Server 4.2
Bea Tuxedo 6.5
Bea Weblogic Server 5.1
Bea Tuxedo 6.3
Bea Tuxedo 6.4
Bea Tuxedo 8.1
Bea Weblogic Server 5.0.1
1 EDB exploit
NA
CVE-2003-0622
The Administration Console for BEA Tuxedo 8.1 and previous versions allows remote malicious users to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.
Bea Tuxedo 8.0
Bea Tuxedo 7.1
Bea Weblogic Server 4.2
Bea Tuxedo 6.5
Bea Weblogic Server 5.1
Bea Tuxedo 6.3
Bea Tuxedo 6.4
Bea Tuxedo 8.1
Bea Weblogic Server 5.0.1
NA
CVE-2003-0623
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and previous versions allows remote malicious users to inject arbitrary web script via the INIFILE argument.
Bea Tuxedo 8.0
Bea Tuxedo 7.1
Bea Weblogic Server 4.2
Bea Tuxedo 6.5
Bea Weblogic Server 5.1
Bea Tuxedo 6.3
Bea Tuxedo 6.4
Bea Tuxedo 8.1
Bea Weblogic Server 5.0.1
NA
CVE-2005-4754
BEA WebLogic Server and WebLogic Express 8.1 SP3 and previous versions allow remote malicious users to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation."
Bea Weblogic Server 8.1
NA
CVE-2005-4758
Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and previous versions allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed through ...
Bea Weblogic Server 8.1
NA
CVE-2004-2424
BEA WebLogic Server and WebLogic Express 8.1 up to and including 8.1 SP2 allow remote malicious users to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.
Bea Weblogic Server 8.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-0044
client side
CVE-2021-47601
deserialization
CVE-2024-34994
encryption
CVE-2021-47609
CVE-2024-37079
CVE-2024-38608
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »