The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 75.2%