PT-2005-5424 · Bea · Oracle Weblogic Server+1

Publicado

2005-12-31

·

Atualizado

2008-09-05

·

CVE-2005-4761

CVSS v2.0

1.2

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 8.1 SP4 and earlier BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier BEA WebLogic Server and WebLogic Express versions 6.1 SP7 and earlier
Description The software logs the Java command line at server startup, potentially including sensitive information such as passwords or keyphrases in the server log file when the -D option is used.
Recommendations For versions 8.1 SP4 and earlier, consider removing or restricting access to the server log file to minimize exposure of sensitive information. For versions 7.0 SP5 and earlier, avoid using the -D option to prevent logging of sensitive data. For versions 6.1 SP7 and earlier, restrict access to the server log file and consider alternative logging configurations to reduce the risk of sensitive information disclosure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4761

Produtos afetados

Weblogic Express
Oracle Weblogic Server