AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-0418

HIGH · CVSS 7.5 EPSS 1.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-01-23 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-0418
Severity
HIGH
CVSS
7.5
EPSS
1.61%

Original Filing — NVD Description

BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.