Weblogic Server
Vendor:
First CVE: Jun 8, 2000 · Active for 26 years
150
Total CVEs
More Total CVEs than 99% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Weblogic Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2000
26 years ago
Most Recent CVE
Jul 13, 2010
5,856 days ago
CVE Severity & Scoring
Weblogic Server150 CVEs
11%
63%
26%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (2.0%)
Unknown147 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High0 (0.0%)
Unknown147 (98.0%)
User Interaction
None3 (2.0%)
Unknown147 (98.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.0%)
Unknown147 (98.0%)
Top CVEs
Signals from CVEs in this product scope (150 CVEs).
150 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3257HIGH Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary | Jul 22, 2008 | 10.0 | 88 | NO | YES |
CVE-2001-0098HIGH Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. | Feb 12, 2001 | 10.0 | 77 | NO | YES |
CVE-2004-0204HIGH Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2 | Aug 6, 2004 | 7.5 | 68 | NO | YES |
CVE-2000-0681HIGH Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. | Oct 20, 2000 | 10.0 | 52 | NO | NO |
CVE-2000-0684HIGH BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on | Oct 20, 2000 | 10.0 | 40 | NO | YES |
CVE-2000-0685HIGH BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the s | Oct 20, 2000 | 10.0 | 40 | NO | YES |
CVE-2007-2699HIGH The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative us | May 16, 2007 | 7.1 | 35 | NO | NO |
CVE-2010-2375MEDIUM Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9. | Jul 13, 2010 | 6.4 | 34 | NO | YES |
CVE-2005-1744CRITICAL BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the app | May 24, 2005 | 9.8 | 30 | NO | NO |
CVE-2005-1380MEDIUM Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction a | May 3, 2005 | 6.8 | 28 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (150 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
7.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (150 CVEs).
Media Mentions
Signals from CVEs in this product scope (150 CVEs).
Top CNAs Publishing CVEs For Weblogic Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2 | 15 | 6.6 | 11.8% | 0 | 2 |
| 9.1 | 28 | 6.0 | 7.6% | 0 | 2 |
| 9.0 | 38 | 5.4 | 9.4% | 0 | 2 |
| 8.1 | 97 | 5.6 | 3.4% | 0 | 4 |
| 7.0.0.1 | 26 | 5.2 | 3.7% | 0 | 1 |
| 7.0 | 93 | 5.6 | 2.3% | 0 | 2 |
| 6.1 | 53 | 5.6 | 2.9% | 0 | 2 |
| 6.0 | 17 | 5.8 | 6.2% | 0 | 1 |
| 5.1 | 13 | 5.5 | 10.8% | 0 | 3 |
| 5.0.1 | 3 | 4.8 | 3.3% | 0 | 1 |
| 4.5.2 | 1 | 10.0 | 83.6% | 0 | 1 |
| 4.5.1 | 3 | 10.0 | 47.9% | 0 | 3 |
| 4.5 | 2 | 6.7 | 30.9% | 0 | 2 |
| 4.2 | 3 | 4.8 | 3.3% | 0 | 1 |
| 4.0.4 | 3 | 10.0 | 36.0% | 0 | 3 |
| 4.0 | 2 | 6.7 | 30.9% | 0 | 2 |
| 3.1.8 | 5 | 7.4 | 20.1% | 0 | 5 |
| 10.0 | 10 | 6.5 | 10.6% | 0 | 1 |