BEA Systems developed a focused suite of enterprise middleware and application server products, particularly WebLogic Server and its integration-oriented companions, that sit in the request and transaction path of large-scale business systems. The vendor's vulnerability footprint, despite its modest product count, reflects the prominence of these widely deployed platforms in the enterprise landscape. Its disclosed weaknesses center on authentication flaws, information exposure, and input-handling issues such as cross-site scripting, which are characteristic of complex server-side Java applications and middleware processing untrusted requests. A moderate tendency toward public exploit availability characterizes this vendor's disclosures. Defenders should treat WebLogic Server advisories as high-priority given its pervasive deployment in business-critical environments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bea over time
Signals from CVEs in this vendor scope (159 CVEs).
159 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3257HIGH Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary | Jul 22, 2008 | 10.0 | 88 | NO | YES |
CVE-2001-0098HIGH Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. | Feb 12, 2001 | 10.0 | 77 | NO | YES |
CVE-2004-0204HIGH Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2 | Aug 6, 2004 | 7.5 | 68 | NO | YES |
CVE-2000-0681HIGH Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. | Oct 20, 2000 | 10.0 | 52 | NO | NO |
CVE-2000-0684HIGH BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on | Oct 20, 2000 | 10.0 | 40 | NO | YES |
CVE-2000-0685HIGH BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the s | Oct 20, 2000 | 10.0 | 40 | NO | YES |
CVE-2007-2699HIGH The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative us | May 16, 2007 | 7.1 | 35 | NO | NO |
CVE-2010-2375MEDIUM Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9. | Jul 13, 2010 | 6.4 | 34 | NO | YES |
CVE-2005-1744CRITICAL BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the app | May 24, 2005 | 9.8 | 30 | NO | NO |
CVE-2005-1380MEDIUM Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction a | May 3, 2005 | 6.8 | 28 | NO | YES |
Signals from CVEs in this vendor scope (159 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bea.
Media articles that mention a CVE ID that affects a product developed by Bea — matched by CVE ID, not by vendor name.