CVE-2008-0895
22.02.2008, 21:44
BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bea | weblogic_server | 6.1 |
| bea | weblogic_server | 6.1:sp1 |
| bea | weblogic_server | 6.1:sp2 |
| bea | weblogic_server | 6.1:sp3 |
| bea | weblogic_server | 6.1:sp4 |
| bea | weblogic_server | 6.1:sp5 |
| bea | weblogic_server | 6.1:sp6 |
| bea | weblogic_server | 6.1:sp7 |
| bea | weblogic_server | 7.0 |
| bea | weblogic_server | 7.0:sp1 |
| bea | weblogic_server | 7.0:sp2 |
| bea | weblogic_server | 7.0:sp3 |
| bea | weblogic_server | 7.0:sp4 |
| bea | weblogic_server | 7.0:sp5 |
| bea | weblogic_server | 7.0:sp6 |
| bea | weblogic_server | 7.0:sp7 |
| bea | weblogic_server | 8.1 |
| bea | weblogic_server | 8.1:sp1 |
| bea | weblogic_server | 8.1:sp2 |
| bea | weblogic_server | 8.1:sp3 |
| bea | weblogic_server | 8.1:sp4 |
| bea | weblogic_server | 8.1:sp5 |
| bea | weblogic_server | 8.1:sp6 |
| bea | weblogic_server | 9.0 |
| bea | weblogic_server | 9.1 |
| bea | weblogic_server | 9.2 |
| bea | weblogic_server | 10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References