Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bea Systems

First CVE: Feb 21, 2008Active for: 18 yearsTotal CVEs: 14
32.6
VTI Score
Medium

BEA Systems' vulnerability profile centers on its WebLogic application server and portal products, which sit in the enterprise middleware and request-handling tier of large deployments. The recurring weakness classes—cross-site scripting, sensitive information disclosure, link-following flaws, and memory-safety issues—reflect the complexity of web request processing and server-side templating in a J2EE platform, and the vendor's disclosures tend to acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bea Systems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2008
18 years ago
Most Recent CVE
Jul 13, 2010
5,855 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3257HIGH
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary
Jul 22, 200810.088NOYES
CVE-2010-2375MEDIUM
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.
Jul 13, 20106.434NOYES
CVE-2008-0904HIGH
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary
Feb 22, 20087.823NONO
CVE-2008-0900MEDIUM
Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknow
Feb 22, 20086.022NONO
CVE-2008-0901HIGH
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted
Feb 22, 20087.122NONO
CVE-2008-0870HIGH
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http
Feb 21, 20087.519NONO
CVE-2008-0896MEDIUM
BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which a
Feb 22, 20084.916NONO
CVE-2008-0902MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspec
Feb 22, 20084.316NONO
CVE-2008-0903MEDIUM
Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause
Feb 22, 20084.316NONO
CVE-2008-0868MEDIUM
Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web scri
Feb 21, 20084.316NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
71%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bea Systems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bea Systems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bea Systems's Products

View all 2 CNAs →

Top CWEs