Known Vulnerabilities for products from Bea Systems

Listed below are 14 of the newest known vulnerabilities associated with the vendor "Bea Systems".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-35383 Not Provided 2026-04-02 2026-04-02
CVE-2026-34990 Not Provided 2026-04-03 2026-04-03
CVE-2026-34980 Not Provided 2026-04-03 2026-04-03
CVE-2026-34979 Not Provided 2026-04-03 2026-04-03
CVE-2026-34978 Not Provided 2026-04-03 2026-04-03
CVE-2026-34545 Not Provided 2026-04-01 2026-04-01
CVE-2026-34450 Not Provided 2026-03-31 2026-04-01
CVE-2026-34172 Not Provided 2026-03-31 2026-03-31
CVE-2026-34155 Not Provided 2026-03-31 2026-03-31
CVE-2026-33995 Not Provided 2026-03-30 2026-03-30
CVE-2010-2375 Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in ... 6.4 - MEDIUM 2010-07-13 2018-10-30
CVE-2008-3257 Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 an... 10 - HIGH 2008-07-22 2017-09-29
CVE-2008-0904 Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2... 7.8 - HIGH 2008-02-22 2011-03-08
CVE-2008-0903 Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before... 4.3 - MEDIUM 2008-02-22 2011-03-08
CVE-2008-0902 Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote atta... 4.3 - MEDIUM 2008-02-22 2011-03-08
CVE-2008-0901 BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, ev... 7.1 - HIGH 2008-02-22 2018-10-15
CVE-2008-0900 Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remot... 6 - MEDIUM 2008-02-22 2011-03-08
CVE-2008-0896 BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes e... 4.9 - MEDIUM 2008-02-22 2011-03-08
CVE-2008-0870 BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:... 7.5 - HIGH 2008-02-21 2018-10-30
CVE-2008-0869 Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 ... 4.3 - MEDIUM 2008-02-21 2011-03-08