PT-2005-5424 · Bea · Oracle Weblogic Server+1
Publicado
2005-12-31
·
Atualizado
2008-09-05
·
CVE-2005-4761
CVSS v2.0
1.2
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 SP4 and earlier
BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier
BEA WebLogic Server and WebLogic Express versions 6.1 SP7 and earlier
Description
The software logs the Java command line at server startup, potentially including sensitive information such as passwords or keyphrases in the server log file when the -D option is used.
Recommendations
For versions 8.1 SP4 and earlier, consider removing or restricting access to the server log file to minimize exposure of sensitive information.
For versions 7.0 SP5 and earlier, avoid using the -D option to prevent logging of sensitive data.
For versions 6.1 SP7 and earlier, restrict access to the server log file and consider alternative logging configurations to reduce the risk of sensitive information disclosure.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Weblogic Express
Oracle Weblogic Server