Oracle Bea Product Suite vulnerabilities
32 known vulnerabilities affecting oracle/bea_product_suite.
Total CVEs
32
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH1MEDIUM24LOW2
Vulnerabilities
Page 1 of 2
CVE-2010-0079CRITICALCVSS 10.0vr27.6.52010-01-13
CVE-2010-0079 [CRITICAL] CVE-2010-0079: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2,
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-387
nvd
CVE-2010-0078MEDIUMCVSS 5.0v9.0v9.1+3 more2010-01-13
CVE-2010-0078 [MEDIUM] CVE-2010-0078: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0068MEDIUMCVSS 5.0v9.0v9.1+2 more2010-01-13
CVE-2010-0068 [MEDIUM] CVE-2010-0068: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, an
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2010-0069MEDIUMCVSS 4.3v7.0v8.1+5 more2010-01-13
CVE-2010-0069 [MEDIUM] CVE-2010-0069: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0, SP7, 8.1SP6, 9.
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0, SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP1, and 10.3.0 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2010-0074MEDIUMCVSS 5.0v7.0v8.1+5 more2010-01-13
CVE-2010-0074 [MEDIUM] CVE-2010-0074: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0,
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2009-3403CRITICALCVSS 10.0vr27.6.42009-10-22
CVE-2009-3403 [CRITICAL] CVE-2009-3403: Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5,
Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.
nvd
CVE-2009-2002MEDIUMCVSS 4.3v8.1.6v9.2.3+3 more2009-10-22
CVE-2009-2002 [MEDIUM] CVE-2009-2002: Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1.6, 9.2.3, 10.0.1
Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1.6, 9.2.3, 10.0.1, 10.2.1, and 10.3.1.0.0 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2009-3399MEDIUMCVSS 4.3v7.0.62009-10-22
CVE-2009-3399 [MEDIUM] CVE-2009-3399: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0.6 and 8.1.5 allo
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0.6 and 8.1.5 allows remote attackers to affect integrity, related to WLS Console.
nvd
CVE-2009-3396MEDIUMCVSS 4.3v9.0v9.1+3 more2009-10-22
CVE-2009-3396 [MEDIUM] CVE-2009-3396: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.0.1, and 10.3 allows remote attackers to affect integrity, related to WLS Console.
nvd
CVE-2009-0217MEDIUMCVSS 5.0v8.1v9.0+4 more2009-07-14
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented i
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.
nvd
CVE-2009-1974MEDIUMCVSS 6.8v7.0v8.1+5 more2009-07-14
CVE-2009-1974 [MEDIUM] CVE-2009-1974: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package.
nvd
CVE-2009-1975MEDIUMCVSS 6.8PoCv10.32009-07-14
CVE-2009-1975 [MEDIUM] CVE-2009-1975: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote a
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package.
nvd
CVE-2009-1012CRITICALCVSS 10.0v7.0v8.1+5 more2009-04-15
CVE-2009-1012 [CRITICAL] CVE-2009-1012: Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Serv
Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU.
nvd
CVE-2009-1016HIGHCVSS 8.5v7.0v8.1+5 more2009-04-15
CVE-2009-1016 [HIGH] CVE-2009-1016: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2009-1004MEDIUMCVSS 4.0v10.32009-04-15
CVE-2009-1004 [MEDIUM] CVE-2009-1004: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote a
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-1002MEDIUMCVSS 5.8v7.0v8.1+5 more2009-04-15
CVE-2009-1002 [MEDIUM] CVE-2009-1002: Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold throug
Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold through MP3, 9.1, 9.0, 8.1 Gold through SP6, and 7.0 Gold through SP7 allows remote attackers to gain privileges via unknown vectors.
nvd
CVE-2009-1005MEDIUMCVSS 4.1v3.0v3.0.1+2 more2009-04-15
CVE-2009-1005 [MEDIUM] CVE-2009-1005: Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) c
Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1003MEDIUMCVSS 5.0v9.0v9.1+3 more2009-04-15
CVE-2009-1003 [MEDIUM] CVE-2009-1003: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors related to "access to source code of web pages."
nvd
CVE-2009-1001MEDIUMCVSS 5.5v8.12009-04-15
CVE-2009-1001 [MEDIUM] CVE-2009-1001: Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authentic
Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.
nvd
CVE-2008-5457CRITICALCVSS 10.0PoCv7.0v8.1+5 more2009-01-14
CVE-2008-5457 [CRITICAL] CVE-2008-5457: Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web serv
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
1 / 2Next →