← Vulnerability feed

Vulnerability record · CVE-2009-3403 · published 22 October 2009

CVE-2009-3403: Oracle bea product suite vulnerability

Oracle · Bea Product Suite

Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.

10.0 CVSS 2.0 High EPSS 3.1% · top 12.9%
10.0CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3403 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0079Oracle bea product suite vulnerabilityMultiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confide…EPSS 3.1%10.0CVE-2009-1012Oracle bea product suite vulnerabilityUnspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.…EPSS 3.9%10.0CVE-2008-5457Oracle BEA WebLogic Server Plugins unspecified remote vulnerabilityAn unspecified vulnerability exists in the Oracle BEA WebLogic Server Plugins component for Apache, Sun and IIS web servers within BEA Product Suite …EPSS 61%analysed10.0CVE-2008-4008WebLogic Apache Connector stack buffer overflow in BEA Product SuiteAn unspecified vulnerability in the WebLogic Server Plugins for Apache component of BEA Product Suite (versions 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.…EPSS 56%analysed8.5CVE-2009-1016Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote…EPSS 2.0%6.8CVE-2009-1974Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote…EPSS 1.5%6.8CVE-2009-1975Oracle bea product suite vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, an…EPSS 2.7%6.8CVE-2008-5461Oracle bea product suite information exposure vulnerabilityUnspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remot…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2009-3403), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.