CVE-2008-0901
 
Severity Score
7.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
BEA WebLogic Server y Express de 7.0 a 10.0 permite a atacantes remotos llevar a cabo ataques para adivinar contraseñas mediante fuerza bruta, incluso cuando se ha activado el cierre de cuenta, a través de URLs manipulados que indican si la contraseña supuesta es buena o no.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-02-22 CVE Reserved
- 2008-02-22 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-255: Credentials Management Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/29041 | Third Party Advisory | |
http://www.s21sec.com/avisos/s21sec-040-en.txt | X_refsource_misc | |
http://www.securityfocus.com/archive/1/488686/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019449 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0612/references | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://dev2dev.bea.com/pub/advisory/271 | 2018-10-15 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp6 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp7 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp6 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.0 Search vendor "Bea" for product "Weblogic Server" and version "9.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.1 Search vendor "Bea" for product "Weblogic Server" and version "9.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.2 Search vendor "Bea" for product "Weblogic Server" and version "9.2" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.2 Search vendor "Bea" for product "Weblogic Server" and version "9.2" | mp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 9.2 Search vendor "Bea" for product "Weblogic Server" and version "9.2" | mp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 10.0 Search vendor "Bea" for product "Weblogic Server" and version "10.0" | - |
Affected
| ||||||
Bea Systems Search vendor "Bea Systems" | Weblogic Server Search vendor "Bea Systems" for product "Weblogic Server" | 10.0_mp1 Search vendor "Bea Systems" for product "Weblogic Server" and version "10.0_mp1" | - |
Affected
|