Oracle Bea Product Suite vulnerabilities
32 known vulnerabilities affecting oracle/bea_product_suite.
Total CVEs
32
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH1MEDIUM24LOW2
Vulnerabilities
Page 1 of 2
CVE-2008-5457P2CRITICALCVSS 10.0PoCv7.0v8.1+5 more2009-01-14
CVE-2008-5457 [CRITICAL] CVE-2008-5457: Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web serv
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-4008P2CRITICALCVSS 10.0PoCv6.1v7.0+6 more2008-10-14
CVE-2008-4008 [CRITICAL] CVE-2008-4008: Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 1
Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented
nvd
CVE-2009-1975P3MEDIUMCVSS 6.8PoCv10.32009-07-14
CVE-2009-1975 [MEDIUM] CVE-2009-1975: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote a
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package.
nvd
CVE-2010-0079P3CRITICALCVSS 10.0vr27.6.52010-01-13
CVE-2010-0079 [CRITICAL] CVE-2010-0079: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2,
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-387
nvd
CVE-2009-1012P3CRITICALCVSS 10.0v7.0v8.1+5 more2009-04-15
CVE-2009-1012 [CRITICAL] CVE-2009-1012: Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Serv
Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU.
nvd
CVE-2009-3403P3CRITICALCVSS 10.0vr27.6.42009-10-22
CVE-2009-3403 [CRITICAL] CVE-2009-3403: Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5,
Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.
nvd
CVE-2009-1016P3HIGHCVSS 8.5v7.0v8.1+5 more2009-04-15
CVE-2009-1016 [HIGH] CVE-2009-1016: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2009-0217P3MEDIUMCVSS 5.0v8.1v9.0+4 more2009-07-14
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented i
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.
nvd
CVE-2009-1974P4MEDIUMCVSS 6.8v7.0v8.1+5 more2009-07-14
CVE-2009-1974 [MEDIUM] CVE-2009-1974: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package.
nvd
CVE-2008-4010P4MEDIUMCVSS 6.8v8.1v9.2+3 more2008-10-14
CVE-2008-4010 [MEDIUM] CVE-2008-4010: Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite 10.3, 10.2, 10.0 M
Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to "some NetUI tags."
nvd
CVE-2008-5462P4MEDIUMCVSS 6.8v8.1v9.2+3 more2009-01-14
CVE-2008-5462 [MEDIUM] CWE-264 CVE-2008-5462: Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1
Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-4013P4MEDIUMCVSS 6.8v8.1v9.0+3 more2008-10-14
CVE-2008-4013 [MEDIUM] CVE-2008-4013: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.0 MP1, 9.2 MP3, 9
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1002P4MEDIUMCVSS 5.8v7.0v8.1+5 more2009-04-15
CVE-2009-1002 [MEDIUM] CVE-2009-1002: Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold throug
Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold through MP3, 9.1, 9.0, 8.1 Gold through SP6, and 7.0 Gold through SP7 allows remote attackers to gain privileges via unknown vectors.
nvd
CVE-2008-5461P4MEDIUMCVSS 6.8v7.0v8.1+5 more2009-01-14
CVE-2008-5461 [MEDIUM] CWE-200 CVE-2008-5461: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remote attackers to affect confidentiality, integrity, and availability, related to WLS. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher cl
nvd
CVE-2009-1001P4MEDIUMCVSS 5.5v8.12009-04-15
CVE-2009-1001 [MEDIUM] CVE-2009-1001: Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authentic
Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.
nvd
CVE-2008-4009P4MEDIUMCVSS 5.1v9.12008-10-14
CVE-2008-4009 [MEDIUM] CVE-2008-4009: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.1, when configurin
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.1, when configuring multiple authorizers, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0068P4MEDIUMCVSS 5.0v9.0v9.1+2 more2010-01-13
CVE-2010-0068 [MEDIUM] CVE-2010-0068: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, an
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2010-0074P4MEDIUMCVSS 5.0v7.0v8.1+5 more2010-01-13
CVE-2010-0074 [MEDIUM] CVE-2010-0074: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0,
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0078P4MEDIUMCVSS 5.0v9.0v9.1+3 more2010-01-13
CVE-2010-0078 [MEDIUM] CVE-2010-0078: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2009-3396P4MEDIUMCVSS 4.3v9.0v9.1+3 more2009-10-22
CVE-2009-3396 [MEDIUM] CVE-2009-3396: Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.0.1, and 10.3 allows remote attackers to affect integrity, related to WLS Console.
nvd
1 / 2Next →