PT-2006-1493 · Bea · Bea Weblogic Server+1
Publicado
2006-01-25
·
Atualizado
2017-07-20
·
CVE-2006-0426
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 through SP4
Description
The issue allows attackers to gain privileges by storing old and new passwords in cleartext in the DefaultAuditRecorder.log file when configuration auditing is enabled and a password change occurs.
Recommendations
For BEA WebLogic Server and WebLogic Express versions 8.1 through SP4, consider disabling configuration auditing until a fix is available to prevent cleartext password storage in the DefaultAuditRecorder.log file.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bea Weblogic Server
Weblogic Express