Bea Vulnerabilities

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

BEA WebLogic Server132
BEA WebLogic52
BEA WebLogic Portal26
BEA Tuxedo10
BEA Aqualogic Service Bus4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Remediation

Official Fix112
Temporary Fix0
Workaround4
Unavailable0
Not Defined124

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploitability

High0
Functional0
Proof-of-Concept144
Unproven0
Not Defined96

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Access Vector

Not Defined0
Physical0
Local36
Adjacent14
Network190

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Authentication

Not Defined0
High0
Low24
None216

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

User Interaction

Not Defined0
Required24
None216

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

C3BM Index

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Base

≤10
≤20
≤30
≤420
≤520
≤684
≤742
≤860
≤96
≤108

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Temp

≤10
≤20
≤30
≤424
≤554
≤670
≤754
≤828
≤94
≤106

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

VulDB

≤10
≤20
≤30
≤420
≤520
≤684
≤742
≤860
≤96
≤108

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

NVD

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CNA

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Research

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit 0-day

<1k0
<2k0
<5k24
<10k78
<25k92
<50k46
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Today

<1k180
<2k24
<5k20
<10k16
<25k0
<50k0
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Market Volume

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

🔴 CTI Activities

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Affected Products (16): AquaLogic Interaction (2), AquaLogic Service Bus (1), Aqualogic Service Bus (2), BEA WebLogic Portal (1), JRockit (1), Plumtree Collaboration (1), Plumtree Foundation (1), Tuxedo (6), WebLogic (71), WebLogic Mobility Server (1), WebLogic Portal (23), WebLogic Server (124), WebLogic Workshop (3), Weblogic (1), Weblogic Integration (1), Weblogic Workshop (1)

Link to Vendor Website: https://www.oracle.com/corporate/acquisitions/bea/

PublishedBaseTempVulnerabilityProdExpRemEPSSCTICVE
07/22/200810.010.0BEA WebLogic Server mod_wl .jsp memory corruptionApplication Server SoftwareHighNot Defined0.932690.00CVE-2008-3257
02/22/20085.34.8BEA WebLogic Server denial of serviceApplication Server SoftwareProof-of-ConceptOfficial Fix0.006000.00CVE-2008-0903
02/22/20084.34.1BEA WebLogic Server cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002430.00CVE-2008-0902
02/22/20087.57.1BEA WebLogic Server credentials managementApplication Server SoftwareProof-of-ConceptNot Defined0.006090.00CVE-2008-0901
02/22/20086.36.0BEA WebLogic Server access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002310.00CVE-2008-0900
02/22/20084.34.1BEA WebLogic Server Administration Console cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002790.00CVE-2008-0899
02/22/20086.56.2BEA WebLogic Server Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002560.00CVE-2008-0898
02/22/20088.17.7BEA WebLogic Server Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002310.02CVE-2008-0897
02/22/20085.44.9BEA WebLogic Portal Access Restriction access controlApplication Server SoftwareProof-of-ConceptOfficial Fix0.000760.00CVE-2008-0896
02/22/20086.56.2BEA WebLogic Server improper authenticationApplication Server SoftwareProof-of-ConceptNot Defined0.003040.00CVE-2008-0895
02/20/20087.36.9BEA WebLogic Portal Administration Console link followingApplication Server SoftwareProof-of-ConceptNot Defined0.008600.00CVE-2008-0870
02/20/20084.33.9BEA WebLogic Workshop UI Framework cross site scriptingApplication Server SoftwareProof-of-ConceptOfficial Fix0.004560.00CVE-2008-0869
02/20/20084.33.9BEA WebLogic Portal cross site scriptingApplication Server SoftwareProof-of-ConceptOfficial Fix0.002380.00CVE-2008-0868
02/20/20084.33.9BEA Plumtree Foundation cross site scriptingUnknownProof-of-ConceptOfficial Fix0.004520.00CVE-2008-0867
02/20/20084.34.1BEA WebLogic Workshop cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002790.00CVE-2008-0866
02/20/20085.35.0BEA WebLogic Portal access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002930.00CVE-2008-0865
02/20/20085.35.0BEA WebLogic Portal Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002930.00CVE-2008-0864
02/20/20085.35.0BEA WebLogic Server information disclosureApplication Server SoftwareProof-of-ConceptNot Defined0.002940.00CVE-2008-0863
02/19/20087.56.7BEA Plumtree Collaboration information disclosureGroupware SoftwareProof-of-ConceptOfficial Fix0.004630.00CVE-2008-0904
12/12/20077.36.9BEA WebLogic Mobility Server improper authenticationApplication Server SoftwareProof-of-ConceptNot Defined0.020560.00CVE-2007-6384
12/01/20075.35.0BEA AquaLogic Interaction information disclosureUnknownProof-of-ConceptNot Defined0.023580.00CVE-2007-6198
12/01/20075.35.0BEA AquaLogic Interaction information disclosureUnknownProof-of-ConceptNot Defined0.012550.00CVE-2007-6197
08/30/20076.56.2BEA WebLogic Server information disclosureApplication Server SoftwareHighOfficial Fix0.008730.00CVE-2007-4616
08/30/20076.56.2BEA WebLogic Server unknown vulnerabilityApplication Server SoftwareProof-of-ConceptNot Defined0.012150.00CVE-2007-4615
08/28/20077.56.5BEA WebLogic Server denial of serviceApplication Server SoftwareProof-of-ConceptOfficial Fix0.010940.00CVE-2007-4618

215 more entries are not shown

Do you need the next level of professionalism?

Upgrade your account now!