S21Sec Advisory – BEA Weblogic versions 7.0sp6, 8.1sp4, and 9.0sp2 suffer from a flaw where it is possible to launch a credential brute force attack against known users through an internal servlet that permits the bypass of the user locking mechanism.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64007/s21sec-040-en.txt
Source: https://packetstormsecurity.com/files/64007/s21sec-040-en.txt.html