Bea Vulnerabilities

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

BEA WebLogic Server118
BEA WebLogic70
BEA WebLogic Portal28
BEA Tuxedo6
BEA Weblogic Integration2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Remediation

Official Fix126
Temporary Fix0
Workaround2
Unavailable0
Not Defined112

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploitability

High2
Functional0
Proof-of-Concept148
Unproven4
Not Defined86

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Access Vector

Not Defined0
Physical0
Local36
Adjacent8
Network196

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Authentication

Not Defined0
High0
Low40
None200

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

User Interaction

Not Defined0
Required22
None218

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

C3BM Index

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Base

≤10
≤20
≤30
≤424
≤522
≤686
≤728
≤862
≤910
≤108

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Temp

≤10
≤20
≤30
≤428
≤562
≤662
≤754
≤826
≤92
≤106

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

VulDB

≤10
≤20
≤30
≤424
≤522
≤686
≤728
≤862
≤910
≤108

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

NVD

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CNA

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Research

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit 0-day

<1k0
<2k0
<5k16
<10k72
<25k118
<50k34
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Today

<1k200
<2k16
<5k16
<10k8
<25k0
<50k0
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Market Volume

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

🔴 CTI Activities

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Affected Products (16): AquaLogic Interaction (2), AquaLogic Service Bus (1), Aqualogic Service Bus (2), BEA WebLogic Portal (1), JRockit (1), Plumtree Collaboration (1), Plumtree Foundation (1), Tuxedo (6), WebLogic (71), WebLogic Mobility Server (1), WebLogic Portal (23), WebLogic Server (124), WebLogic Workshop (3), Weblogic (1), Weblogic Integration (1), Weblogic Workshop (1)

Link to Vendor Website: https://www.oracle.com/corporate/acquisitions/bea/

PublishedBaseTempVulnerabilityProdExpRemEPSSCTICVE
07/22/200810.010.0BEA WebLogic Server mod_wl .jsp memory corruptionApplication Server SoftwareHighNot Defined0.932690.00CVE-2008-3257
02/22/20085.34.8BEA WebLogic Server denial of serviceApplication Server SoftwareProof-of-ConceptOfficial Fix0.006000.00CVE-2008-0903
02/22/20084.34.1BEA WebLogic Server cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002430.00CVE-2008-0902
02/22/20087.57.1BEA WebLogic Server credentials managementApplication Server SoftwareProof-of-ConceptNot Defined0.006090.00CVE-2008-0901
02/22/20086.36.0BEA WebLogic Server access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002310.00CVE-2008-0900
02/22/20084.34.1BEA WebLogic Server Administration Console cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002790.00CVE-2008-0899
02/22/20086.56.2BEA WebLogic Server Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002560.00CVE-2008-0898
02/22/20088.17.7BEA WebLogic Server Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002310.02CVE-2008-0897
02/22/20085.44.9BEA WebLogic Portal Access Restriction access controlApplication Server SoftwareProof-of-ConceptOfficial Fix0.000760.00CVE-2008-0896
02/22/20086.56.2BEA WebLogic Server improper authenticationApplication Server SoftwareProof-of-ConceptNot Defined0.003040.00CVE-2008-0895
02/20/20087.36.9BEA WebLogic Portal Administration Console link followingApplication Server SoftwareProof-of-ConceptNot Defined0.008600.00CVE-2008-0870
02/20/20084.33.9BEA WebLogic Workshop UI Framework cross site scriptingApplication Server SoftwareProof-of-ConceptOfficial Fix0.004560.00CVE-2008-0869
02/20/20084.33.9BEA WebLogic Portal cross site scriptingApplication Server SoftwareProof-of-ConceptOfficial Fix0.002380.00CVE-2008-0868
02/20/20084.33.9BEA Plumtree Foundation cross site scriptingUnknownProof-of-ConceptOfficial Fix0.004520.00CVE-2008-0867
02/20/20084.34.1BEA WebLogic Workshop cross site scriptingApplication Server SoftwareProof-of-ConceptNot Defined0.002790.00CVE-2008-0866
02/20/20085.35.0BEA WebLogic Portal access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002930.00CVE-2008-0865
02/20/20085.35.0BEA WebLogic Portal Access Restriction access controlApplication Server SoftwareProof-of-ConceptNot Defined0.002930.00CVE-2008-0864
02/20/20085.35.0BEA WebLogic Server information disclosureApplication Server SoftwareProof-of-ConceptNot Defined0.002940.00CVE-2008-0863
02/19/20087.56.7BEA Plumtree Collaboration information disclosureGroupware SoftwareProof-of-ConceptOfficial Fix0.004630.00CVE-2008-0904
12/12/20077.36.9BEA WebLogic Mobility Server improper authenticationApplication Server SoftwareProof-of-ConceptNot Defined0.020560.00CVE-2007-6384
12/01/20075.35.0BEA AquaLogic Interaction information disclosureUnknownProof-of-ConceptNot Defined0.023580.00CVE-2007-6198
12/01/20075.35.0BEA AquaLogic Interaction information disclosureUnknownProof-of-ConceptNot Defined0.012550.00CVE-2007-6197
08/30/20076.56.2BEA WebLogic Server information disclosureApplication Server SoftwareHighOfficial Fix0.008730.00CVE-2007-4616
08/30/20076.56.2BEA WebLogic Server unknown vulnerabilityApplication Server SoftwareProof-of-ConceptNot Defined0.012150.00CVE-2007-4615
08/28/20077.56.5BEA WebLogic Server denial of serviceApplication Server SoftwareProof-of-ConceptOfficial Fix0.010940.00CVE-2007-4618

215 more entries are not shown

Do you need the next level of professionalism?

Upgrade your account now!