PT-2006-1493 · Bea · Bea Weblogic Server+1
Published
2006-01-25
·
Updated
2017-07-20
·
CVE-2006-0426
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server and WebLogic Express versions 8.1 through SP4
Description
The issue allows attackers to gain privileges by storing old and new passwords in cleartext in the DefaultAuditRecorder.log file when configuration auditing is enabled and a password change occurs.
Recommendations
For BEA WebLogic Server and WebLogic Express versions 8.1 through SP4, consider disabling configuration auditing until a fix is available to prevent cleartext password storage in the DefaultAuditRecorder.log file.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server
Weblogic Express