BEA WebLogic Server is "the world leading application server software". It's possible to launch a credentials brute force attack against known users through an BEA WebLogic Server's internal servlet that permits the bypass of the user locking mechanism.
http://www.securiteam.com/securitynews/5HP0O1FNFI.html