CVE-2008-0901
BEA Weblogic Server - Information Disclosure
Title source: ruleDescription
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
References (6)
Scores
EPSS
0.0074
EPSS Percentile
72.6%
Classification
CWE
CWE-200
CWE-255
Status
draft
Affected Products (22)
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
bea/weblogic_server
... and 7 more
Timeline
Published
Feb 22, 2008
Tracked Since
Feb 18, 2026