BEA Systems WebLogic Server 4.5.2 SP2

CPE Details

BEA Systems WebLogic Server 4.5.2 SP2
4.5.2
2007-08-23
19h16 +00:00
2008-04-07
11h42 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:bea:weblogic_server:4.5.2:sp2:*:*:*:*:*:*

Informations

Vendor

bea

Product

weblogic_server

Version

4.5.2

Update

sp2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2008-3257 2008-07-22 14h00 +00:00 Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
10
CVE-2007-0419 2007-01-22 23h00 +00:00 The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).
5
CVE-2007-0424 2007-01-22 23h00 +00:00 Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.
5
CVE-2005-1744 2005-05-24 02h00 +00:00 BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
9.8
Critical
CVE-2003-0624 2003-11-05 04h00 +00:00 Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
4.3
CVE-2003-0640 2003-08-02 02h00 +00:00 BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
10
CVE-2001-0098 2001-02-02 04h00 +00:00 Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
10
CVE-2000-0681 2000-10-13 02h00 +00:00 Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
10