Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq3p-2788-w982

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

EPSS

Процентиль: 72%
0.0074
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 18 лет назад

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

EPSS

Процентиль: 72%
0.0074
Низкий

Дефекты

CWE-200