Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bea

First CVE: Jun 8, 2000Active for: 26 yearsTotal CVEs: 159
34.2
VTI Score
Medium

BEA Systems developed a focused suite of enterprise middleware and application server products, particularly WebLogic Server and its integration-oriented companions, that sit in the request and transaction path of large-scale business systems. The vendor's vulnerability footprint, despite its modest product count, reflects the prominence of these widely deployed platforms in the enterprise landscape. Its disclosed weaknesses center on authentication flaws, information exposure, and input-handling issues such as cross-site scripting, which are characteristic of complex server-side Java applications and middleware processing untrusted requests. A moderate tendency toward public exploit availability characterizes this vendor's disclosures. Defenders should treat WebLogic Server advisories as high-priority given its pervasive deployment in business-critical environments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
159
Total CVEs
More Total CVEs than 100% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bea over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2000
26 years ago
Most Recent CVE
Jul 13, 2010
5,855 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (159 CVEs).

159 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3257HIGH
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary
Jul 22, 200810.088NOYES
CVE-2001-0098HIGH
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
Feb 12, 200110.077NOYES
CVE-2004-0204HIGH
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2
Aug 6, 20047.568NOYES
CVE-2000-0681HIGH
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
Oct 20, 200010.052NONO
CVE-2000-0684HIGH
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on
Oct 20, 200010.040NOYES
CVE-2000-0685HIGH
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the s
Oct 20, 200010.040NOYES
CVE-2007-2699HIGH
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative us
May 16, 20077.135NONO
CVE-2010-2375MEDIUM
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.
Jul 13, 20106.434NOYES
CVE-2005-1744CRITICAL
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the app
May 24, 20059.830NONO
CVE-2005-1380MEDIUM
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction a
May 3, 20056.828NOYES
View all 159 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products159 CVEs
10%
63%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (1.9%)
Unknown156 (98.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (1.9%)
High0 (0.0%)
Unknown156 (98.1%)
User Interaction
None3 (1.9%)
Unknown156 (98.1%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (1.9%)
Unknown156 (98.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (159 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
7.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bea.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bea — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bea's Products

View all 2 CNAs →

Top CWEs