CVE-2008-0901Sensitive Information Exposure in Weblogic Server

Severity
7.1HIGHNVD
EPSS
0.7%
top 27.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 1

Description

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

CVSS vector

AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages2 packages

NVDbea/weblogic_server6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pq3p-2788-w982: BEA WebLogic Server and Express 72022-05-01
CVEList
CVE-2008-0901: BEA WebLogic Server and Express 72008-02-22
CVE-2008-0901 — Sensitive Information Exposure | cvebase