← Back

Bea

bea

158 CVEs • 10 products

Products (10)

Click to collapse
Toggle

CVEs (158)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bea
1Weblogic Server
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
1Bea
1Weblogic Server
Apr 16, 2026
Mar 24, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbit...Show more
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Mar 18, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of th...Show more
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
2.6 LOW· v2
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive info...Show more
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.Show less
1Bea
2Weblogic Integration
Weblogic Server
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not pre...Show more
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that ar...Show more
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
2.6 LOW· v2
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
1Bea
1Weblogic Server
Apr 16, 2026
Mar 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.
1Bea
1Tuxedo
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.
1Bea
1Weblogic Server
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
1Bea
1Weblogic Server
Apr 16, 2026
Dec 31, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricte...Show more
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
1Bea
1Weblogic Server
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
1Bea
1Weblogic Server
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.
1Bea
1Weblogic Server
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.
1Bea
1Weblogic Server
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
1Bea
1Weblogic Server
Apr 16, 2026
Jun 21, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further pro...Show more
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.Show less
1Bea
1Weblogic Server
Apr 16, 2026
Jun 8, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.