VYPR

Weblogic Portal

by Oracle Corporation

CVEs (24)

  • CVE-2005-1742May 24, 2005
    risk 0.00cvss —epss 0.03

    BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

  • CVE-2005-1748May 24, 2005
    risk 0.00cvss —epss 0.03

    The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.

  • CVE-2005-1749May 24, 2005
    risk 0.00cvss —epss 0.03

    Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

  • CVE-2005-1747May 24, 2005
    risk 0.00cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username…

Page 2 of 2