PT-2005-5424 · Bea · Oracle Weblogic Server+1
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-4761
CVSS v2.0
1.2
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 SP4 and earlier
BEA WebLogic Server and WebLogic Express versions 7.0 SP5 and earlier
BEA WebLogic Server and WebLogic Express versions 6.1 SP7 and earlier
Description
The software logs the Java command line at server startup, potentially including sensitive information such as passwords or keyphrases in the server log file when the -D option is used.
Recommendations
For versions 8.1 SP4 and earlier, consider removing or restricting access to the server log file to minimize exposure of sensitive information.
For versions 7.0 SP5 and earlier, avoid using the -D option to prevent logging of sensitive data.
For versions 6.1 SP7 and earlier, restrict access to the server log file and consider alternative logging configurations to reduce the risk of sensitive information disclosure.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblogic Express
Oracle Weblogic Server