CVE Tools

Bea

158 CVEs tracked since 2000. Since Oct 2000, none of them reached CISA KEV.

Bea CVEs per month

Oct 2000 to Jul 2010. Point at a month, or focus the strip and use the arrow keys.
Bea CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-1070
2000-11null or fewer
2000-12null or fewer
2001-01null or fewer
2001-0210
2001-03null or fewer
2001-04null or fewer
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-0310
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-0310
2003-0410
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-0810
2003-0910
2003-10null or fewer
2003-1140
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-0520
2004-0610
2004-0750
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0210
2005-0360
2005-04null or fewer
2005-05100
2005-0610
2005-07null or fewer
2005-08100
2005-09null or fewer
2005-10null or fewer
2005-1140
2005-12null or fewer
2006-01120
2006-0220
2006-0320
2006-04190
2006-05110
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01200
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05100
2007-06null or fewer
2007-07null or fewer
2007-0860
2007-09null or fewer
2007-1040
2007-11null or fewer
2007-1230
2008-01null or fewer
2008-02100
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-0710
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-0710

Products

The products that kept showing up in Bea's monthly top three, with their CVEs summed over those months.

  1. Weblogic Server14929 months
  2. Tuxedo53 months
  3. Weblogic Integration44 months
  4. Weblogic Workshop32 months
  5. Aqualogic Interaction21 month
  6. Aqualogic Service Bus21 month
  7. Jrockit11 month
  8. Liquid Data11 month
  9. Weblogic Mobility Server11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Bea.

  1. CVE-2010-2375Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, ...6.4
  2. CVE-2008-3257Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long H...10.0
  3. CVE-2008-0901BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indica...7.1
  4. CVE-2008-0895BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.6.4
  5. CVE-2008-0899Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs th...4.3
  6. CVE-2008-0898The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed qu...5.8
  7. CVE-2008-0902Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. N...4.3
  8. CVE-2008-0900Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.6.0
  9. CVE-2008-0897Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a ...7.9
  10. CVE-2008-0863BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch furth...5.0
  11. CVE-2008-0869Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "fr...4.3
  12. CVE-2008-0866Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled b...4.3
  13. CVE-2007-6384Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource acce...7.5
  14. CVE-2007-6197The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source...5.0
  15. CVE-2007-6198portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enume...5.0

The record

Peak rank
#3 in Apr 2006
Busiest month shown
Jan 2007, 20 CVEs
Months with a KEV entry
0 since Oct 2000
Monthly snapshots
30 since 2000
Bea's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store