Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

528 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.37%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.
ModificadaMedia (5)0.87%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.
ModificadaBaja (2.1)0.21%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.
ModificadaMedia (5)2.4%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).
ModificadaMedia (5)1.4%—BEA Weblogic Server31/12/200316/6/2026
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.
ModificadaMedia (5)1.2%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.
ModificadaMedia (5)1.8%—BEA TuxedoBEA Weblogic Server1/12/200316/6/2026
La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante argumentos de nombre de ruta que contienen nombres de dispositivos de MS-DOS como CON o AUX.
ModificadaMedia (4.3)3.8%💥 ExploitBEA Weblogic Server1/12/200316/6/2026
Vulnerabilidad de scripts en sitios cruzados en Interactive.jsp de BEA WebLogic 8.1 y anteriores permite a atacantes remotos inyectar script web malicioso mediante el parámetro person.
ModificadaMedia (5)8.0%💥 ExploitBEA TuxedoBEA Weblogic Server1/12/200316/6/2026
La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos determinar la existencia de ficheros fuera de la raíz web mediante rutas modificadas en el argumento INFILE.
ModificadaMedia (4.3)1.5%—BEA TuxedoBEA Weblogic Server1/12/200316/6/2026
Vulnerabilidad de scripts en sitios cruzados en la consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos inyectar script web arbitrario mediante una argumento INFILE.
ModificadaMedia (6.8)1.3%—BEA Liquid DataBEA Weblogic IntegrationBEA Weblogic Server20/10/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other…
ModificadaAlta (10)2.0%—BEA Weblogic Server27/8/200316/6/2026
BEA WebLogic Server y Express, cuando usa NodeManager para iniciar servidores, provee al usuarios Operadores con privilegios para sobreesctibir nombres de usuario y contraseñas, lo que puede permitir a Operadores ganar privielgios de Admin.
ModificadaAlta (7.5)3.9%—BEA Weblogic Server24/3/200316/6/2026
BEA Weblogic Server y Express 6.0 a 7.0 no restringe adecuadamente el acceso a ciertos servlets internos que llevan a cabo funciones administrativas, lo que permite a atacantes remotos leer ficheros arbitrarios o ejecutar código arbitrario.
ModificadaMedia (4.6)0.38%—BEA Weblogic Server18/3/200316/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.
ModificadaAlta (7.5)2.4%—BEA Weblogic Server31/12/200216/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to…
ModificadaBaja (2.6)1.4%—BEA Weblogic Server31/12/200216/6/2026
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
ModificadaAlta (7.5)1.3%—BEA Weblogic IntegrationBEA Weblogic Server31/12/200216/6/2026
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role…
ModificadaBaja (2.6)1.4%—BEA Weblogic Server4/10/200216/6/2026
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
ModificadaMedia (5)7.1%💥 ExploitBEA Weblogic Server25/3/200216/6/2026
El Servidor 6.1 Weblogic de BEA Sistemas, permite a atacantes que remotos causar una negación de servicio vía una serie de peticiones a archivos .JSP que contengan un nombre de dispositivo de MS-DOS.
ModificadaAlta (10)78%💥 ExploitBEA Weblogic Server12/2/200116/6/2026
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
ModificadaAlta (7.5)2.7%—BEA Weblogic Server31/12/200023/9/2026
BEA Systems WebLogic Express y WebLogic Server 5.1 SP1-SP6 permite a atacantes remotos eludir los controles de acceso para páginas JSP o servlet restringidas a través de una URL con múltiples caracteres / (barra diagonal) antes de las páginas restringidas.
ModificadaAlta (10)51%—BEA Weblogic Server20/10/200016/6/2026
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
ModificadaAlta (10)12%💥 ExploitBEA Weblogic Server20/10/200016/6/2026
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
ModificadaMedia (5)1.7%—BEA Weblogic Server20/10/200016/6/2026
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.
ModificadaAlta (10)12%💥 ExploitBEA Weblogic Server20/10/200016/6/2026
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.