PT-2005-5418 · Bea · Bea Weblogic Server+1
Published
2005-12-31
·
Updated
2018-09-27
·
CVE-2005-4755
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express version 8.1 SP3 and earlier
Description
The issue allows local users to potentially obtain cryptographic keys because the private key passphrase is stored in cleartext in the nodemanager.config file or rendered in cleartext on a terminal or in a log file during domain creation with the Configuration Wizard.
Recommendations
For BEA WebLogic Server and WebLogic Express version 8.1 SP3 and earlier, consider restricting access to the nodemanager.config file and log files to minimize the risk of exploitation. As a temporary workaround, avoid using the Configuration Wizard to create domains until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server
Weblogic Express