CVE-2005-1748
https://notcve.org/view.php?id=CVE-2005-1748
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service. • http://dev2dev.bea.com/pub/advisory/131 http://secunia.com/advisories/15486 http://securitytracker.com/id?1014049 http://www.securityfocus.com/bid/13717 http://www.vupen.com/english/advisories/2005/0608 •
CVE-2005-1743
https://notcve.org/view.php?id=CVE-2005-1743
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions. • http://dev2dev.bea.com/pub/advisory/126 http://secunia.com/advisories/15486 http://securitytracker.com/id?1014049 http://www.securityfocus.com/bid/13717 http://www.vupen.com/english/advisories/2005/0603 •
CVE-2005-1742
https://notcve.org/view.php?id=CVE-2005-1742
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools." • http://dev2dev.bea.com/pub/advisory/125 http://secunia.com/advisories/15486 http://securitytracker.com/id?1014049 http://www.securityfocus.com/bid/13717 http://www.vupen.com/english/advisories/2005/0602 •
CVE-2005-1745
https://notcve.org/view.php?id=CVE-2005-1745
The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password. • http://dev2dev.bea.com/pub/advisory/128 http://secunia.com/advisories/15486 http://securitytracker.com/id?1014049 http://www.securityfocus.com/bid/13717 http://www.vupen.com/english/advisories/2005/0605 •
CVE-2005-1380 – BEA WebLogic Server 8.1 / WebLogic Express Administration Console - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1380
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action. • https://www.exploit-db.com/exploits/25546 http://marc.info/?l=bugtraq&m=111472745503010&w=2 http://secunia.com/advisories/15128 http://securitytracker.com/alerts/2005/Apr/1013817.html http://www.osvdb.org/15895 http://www.red-database-security.com/advisory/bea_css_in_admin_console.html http://www.securityfocus.com/bid/13400 https://exchange.xforce.ibmcloud.com/vulnerabilities/20276 •