PT-2005-5424 · Bea · Oracle Weblogic Server+1

Published

2005-12-31

·

Updated

2008-09-05

·

CVE-2005-4761

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 8.1 SP4 and earlier BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier BEA WebLogic Server and WebLogic Express versions 6.1 SP7 and earlier
Description The software logs the Java command line at server startup, potentially including sensitive information such as passwords or keyphrases in the server log file when the -D option is used.
Recommendations For versions 8.1 SP4 and earlier, consider removing or restricting access to the server log file to minimize exposure of sensitive information. For versions 7.0 SP5 and earlier, avoid using the -D option to prevent logging of sensitive data. For versions 6.1 SP7 and earlier, restrict access to the server log file and consider alternative logging configurations to reduce the risk of sensitive information disclosure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4761

Affected Products

Weblogic Express
Oracle Weblogic Server