所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 9.1 on all platforms
* WebLogic Server 9.0 on all platforms
* WebLogic Server 8.1 released through Service Pack 5, on all platforms
* WebLogic Server 7.0 released through Service Pack 7, on all platforms
* WebLogic Server 6.1 released through Service Pack 7, on all platforms
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10.0 released through Maintenance Pack 1
* WebLogic Server 9.2 released through Maintenance Pack 2
* WebLogic Server 9.1 GA release.
* WebLogic Server 9.0 GA release.
* WebLogic Server 8.1 released through Service Pack 6
* WebLogic Server 7.0 released through Service Pack 7
* WebLogic Server 6.1 released through Service Pack 7
3)帐户停止工作时的错误可执行强制攻击
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10.0 released through Maintenance Pack 1
* WebLogic Server 9.2 released through Maintenance Pack 2
* WebLogic Server 9.1 on all platforms
* WebLogic Server 9.0 on all platforms
* WebLogic Server 8.1 released through Service Pack 6
* WebLogic Server 7.0 released through Service Pack 7
4)处理会话时的错误,可通过欺骗用户登录到以下特定链接来劫持用户会话
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10.0
* WebLogic Server 9.2 released through Maintenance Pack 1
* WebLogic Server 8.1 Service Pack 4 through Service Pack 6
5)传递到WebLogic Server Administration Console的不特定输入在返回到用户前没有被准确过滤,这可在用户浏览器浏览受影响的网页时执行任意HTML和脚本代码。
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10.0
* WebLogic Server 9.2 released through Maintenance Pack 1
* WebLogic Server 9.1
* WebLogic Server 9.0
6)分发队列功能中的不特定错误可在受保护的分发队列中绕过安全策略
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10 with no maintenance packs
* WebLogic Server 9.2 released through Maintenance Pack 1
* WebLogic Server 9.1
* WebLogic Server 9.0
7) 从standalone (physical) JMS Topic destination或secured Distributed Topic member destination中接收到的消息存在不特定错误
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10 with no maintenance packs
* WebLogic Server 9.2 released through Maintenance Pack 1
* WebLogic Server 9.1
* WebLogic Server 9.0
所有平台下WebLogic Portal的以下版本都受到影响
* WebLogic Portal 10.0, on all platforms
* WebLogic Portal 9.2 released through Maintenance Pack 1, on all platforms
10)处理HTML头文件请求时的不特定错误可潜在获得对特定应用程序servlet的访问授权
所有平台下WebLogic Server and WebLogic Express的以下版本都受到影响
* WebLogic Server 10.0
* WebLogic 9.2 released through 9.2 Maintenance Pack 1
* WebLogic Server 9.1
* WebLogic Server 9.0
* WebLogic Server 8.1 released through Service Pack 6
* WebLogic Server 7.0 released through Service Pack 7
* WebLogic Server 6.1 released through Service Pack 7
所有平台下WebLogic Workshop和BEA Workshop for WebLogic的以下版本都受到影响
* BEA Workshop for WebLogic 10.0
* BEA Workshop for WebLogic 9.2 released through Maintenance Pack 1
* BEA Workshop for WebLogic 9.1
* BEA Workshop for WebLogic 9.0
* WebLogic Workshop 8.1 released through Service Pack 6