VendorsBea Systemsweblogic_expressall versions
Vulnerabilities

Bea Systems Weblogic Express

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-0900
Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.
Published 2008-02-22 · Modified
6.0EPSS 0.100
CVE-2008-0903
Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL.
Published 2008-02-22 · Modified
4.3EPSS 0.012