CVE-2008-0901

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
beaweblogic_server
7.0
beaweblogic_server
7.0:sp1
beaweblogic_server
7.0:sp2
beaweblogic_server
7.0:sp3
beaweblogic_server
7.0:sp4
beaweblogic_server
7.0:sp5
beaweblogic_server
7.0:sp6
beaweblogic_server
7.0:sp7
beaweblogic_server
8.1
beaweblogic_server
8.1:sp1
beaweblogic_server
8.1:sp2
beaweblogic_server
8.1:sp3
beaweblogic_server
8.1:sp4
beaweblogic_server
8.1:sp5
beaweblogic_server
8.1:sp6
beaweblogic_server
9.0
beaweblogic_server
9.1
beaweblogic_server
9.2
beaweblogic_server
9.2:mp1
beaweblogic_server
9.2:mp2
beaweblogic_server
10.0
bea_systemsweblogic_server
10.0_mp1:_mp1
𝑥
= Vulnerable software versions