PT-2004-1792 · Bea · Bea Weblogic Server
Publicado
2004-07-21
·
Atualizado
2017-07-11
·
CVE-2004-0712
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 8.1 through 8.1 SP2
Description
The configuration tools for BEA WebLogic Server create a log file that contains the administrative username and password in cleartext. This could allow local users to gain privileges.
Recommendations
For BEA WebLogic Server versions 8.1 through 8.1 SP2, consider restricting access to the log files generated by the configuration tools to minimize the risk of exploitation. As a temporary workaround, avoid using the configuration tools until a secure alternative is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bea Weblogic Server