PT-2007-1884 · Bea · Bea Weblogic Server
Publicado
2007-01-23
·
Atualizado
2011-03-08
·
CVE-2007-0413
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 8.1 through 8.1 SP5
Description
The issue allows local users to obtain sensitive information by reading a backup file of config.xml that contains cleartext data after offline editing.
Recommendations
For BEA WebLogic Server versions 8.1 through 8.1 SP5, consider removing or securing the backup file of config.xml after offline editing to prevent unauthorized access to sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bea Weblogic Server