CVE-2008-0901 — Sensitive Information Exposure in Weblogic Server
Severity
7.1HIGHNVD
EPSS
0.7%
top 27.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 22
Latest updateMay 1
Description
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
CVSS vector
AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9