Weblogic Server

Vendor:

First CVE: Jun 8, 2000 · Active for 26 years

150
Total CVEs
More Total CVEs than 99% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Weblogic Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2000
26 years ago
Most Recent CVE
Jul 13, 2010
5,856 days ago

CVE Severity & Scoring

Weblogic Server150 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (2.0%)
Unknown147 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High0 (0.0%)
Unknown147 (98.0%)
User Interaction
None3 (2.0%)
Unknown147 (98.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.0%)
Unknown147 (98.0%)

Top CVEs

Signals from CVEs in this product scope (150 CVEs).

150 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary
Jul 22, 200810.088NOYES
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
Feb 12, 200110.077NOYES
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2
Aug 6, 20047.568NOYES
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
Oct 20, 200010.052NONO
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on
Oct 20, 200010.040NOYES
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the s
Oct 20, 200010.040NOYES
The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Domain Security Policies, which allows remote administrative us
May 16, 20077.135NONO
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.
Jul 13, 20106.434NOYES
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the app
May 24, 20059.830NONO
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction a
May 3, 20056.828NOYES

Exploit Exposure

Signals from CVEs in this product scope (150 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
7.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (150 CVEs).

Media Mentions

Signals from CVEs in this product scope (150 CVEs).

Top CNAs Publishing CVEs For Weblogic Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2156.611.8%02
9.1286.07.6%02
9.0385.49.4%02
8.1975.63.4%04
7.0.0.1265.23.7%01
7.0935.62.3%02
6.1535.62.9%02
6.0175.86.2%01
5.1135.510.8%03
5.0.134.83.3%01
4.5.2110.083.6%01
4.5.1310.047.9%03
4.526.730.9%02
4.234.83.3%01
4.0.4310.036.0%03
4.026.730.9%02
3.1.857.420.1%05
10.0106.510.6%01