Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.3% | — | BEA Weblogic Server | 31/12/2004 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call. | |
| Modificada | Media (5) | 1.5% | — | Korweblog | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en los visores web de Business Objects Crystal Reports 9 and 10, y Crystal Enterprise 9 o 10, usados en Visual Studio .NET 2003 y Outlook 2003 con Business Contact Manager, Microsoft Business Solutions CRM 1.2, y otros productos, permiten a atacantes remotos leer y… | |
| Modificada | Alta (7.2) | 0.39% | — | BEA Weblogic Server | 6/8/2004 | 16/6/2026 | BEA WebLogic Server y WebLogic Express 7.0 a 7.0 Service Pack 4, y 8.1 a 8.1 Service Pack 2 permiten a atacantes obtener el nombre de usuario y contraseña para arrancar el servidor accediendo directamente a ciertos métodos internos. | |
| Modificada | Media (4.6) | 0.36% | — | BEA Weblogic Server | 27/7/2004 | 16/6/2026 | Las herramientes de configuracion (1) config.sh en Unix o (2) config.cmd en Windows de BEA WebLogic Server 8.1 a SP2 crean un fichero de registro que contiene el nombre y la contraseña del administrador en texto claro, lo que podría permitir a usuarios locales ganar privilegios. | |
| Modificada | Media (5.1) | 2.3% | — | BEA Weblogic Server | 27/7/2004 | 16/6/2026 | El proveedor de Autenticación WebLogic en BEA WebLogic Server y WebLogic Express 8.1 hasta SP2 y 7.0 hasta SP4 no elimina relaciones entre miembros cuando se borra un grupo, lo que puede causar que un nuevo grupo con el mismo nombre tenga miembros del grupo antiguo, lo que permite a miembros del grupo ganar… | |
| Modificada | Media (6.4) | 3.2% | — | BEA Weblogic Server | 27/7/2004 | 16/6/2026 | El método remove en una Enterprise JavaBean (EJB) con estado en BEA WebLogic Server y WebLogic Express version 8.1 hasta SP2, 7.0 hasta SP4, y 6.1 a SP6, no comprueba adecuadamente permisos EJB antes de dejar de exportar una habichuela (bean), lo que permite a usuarios remotos autenticados eliminar objetos EJB de… | |
| Modificada | Alta (7.5) | 1.9% | — | BEA Weblogic Server | 27/7/2004 | 16/6/2026 | La característica de coincidencia de patrones en URL de WebLogic Server 6.x encuentra coincidencias en patrones ilegales terminados en "*" como comodines como si fueran el patrón legal "/", lo que podría causar que usuarios remotos se saltaran las restricciones de acceso pretendidas porque los patrones ilegales son… | |
| Modificada | Alta (7.5) | 2.7% | — | BEA Weblogic Server | 7/7/2004 | 16/6/2026 | BEA WebLogic Server y WebLocic Express 7.0 hasta SP5 y 8.1 hasta SP2, cuando se edita weblogic.xml usando WebLocic Builder o el método SecurityRoleAssignmentMBean.toXML, quita de manera inadvertida etiquetas de asignación de papel de seguridad cuando weblogic.xml no tiene una etiqueta de nombre principal, lo que puede… | |
| Modificada | Baja (2.1) | 0.40% | — | BEA Weblogic Server | 7/7/2004 | 16/6/2026 | BEA WebLogic Server y WebLocic Express 7.0 hasta SP5 y 8.1 hasta SP2 no hace cumplir las restricciones de sitio para iniciar y parar servidores a usuarios en los papeles de seguridad Admin y Operator, lo que permite a usuarios no autorizados causar una denegación de servicio (parada del servicio) | |
| Modificada | Media (4.6) | 0.36% | — | BEA Weblogic Server | 13/4/2004 | 16/6/2026 | BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.2% | — | BEA Weblogic Server | 13/4/2004 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers. | |
| Modificada | Media (5) | 1.2% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL. | |
| Modificada | Baja (2.1) | 0.21% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords. | |
| Modificada | Baja (2.1) | 0.21% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access. | |
| Modificada | Media (5) | 1.4% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password. | |
| Modificada | Baja (2.1) | 0.36% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen. | |
| Modificada | Media (5) | 0.87% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions. | |
| Modificada | Alta (7.2) | 1.2% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges. | |
| Modificada | Media (5) | 1.2% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap. | |
| Modificada | Media (5) | 2.4% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI). | |
| Modificada | Media (4.6) | 0.37% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException. | |
| Modificada | Media (4.3) | 0.70% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user. | |
| Modificada | Baja (2.1) | 0.40% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords. | |
| Modificada | Media (5) | 1.8% | — | BEA TuxedoBEA Weblogic Server | 1/12/2003 | 16/6/2026 | La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante argumentos de nombre de ruta que contienen nombres de dispositivos de MS-DOS como CON o AUX. |