CVE-2008-0901

EUVD-2008-0908
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
beaweblogic_server
7.0
beaweblogic_server
7.0:sp1
beaweblogic_server
7.0:sp2
beaweblogic_server
7.0:sp3
beaweblogic_server
7.0:sp4
beaweblogic_server
7.0:sp5
beaweblogic_server
7.0:sp6
beaweblogic_server
7.0:sp7
beaweblogic_server
8.1
beaweblogic_server
8.1:sp1
beaweblogic_server
8.1:sp2
beaweblogic_server
8.1:sp3
beaweblogic_server
8.1:sp4
beaweblogic_server
8.1:sp5
beaweblogic_server
8.1:sp6
beaweblogic_server
9.0
beaweblogic_server
9.1
beaweblogic_server
9.2
beaweblogic_server
9.2:mp1
beaweblogic_server
9.2:mp2
beaweblogic_server
10.0
bea_systemsweblogic_server
10.0_mp1:_mp1
𝑥
= Vulnerable software versions