PT-2006-1493 · Bea · Bea Weblogic Server+1

Published

2006-01-25

·

Updated

2017-07-20

·

CVE-2006-0426

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server and WebLogic Express versions 8.1 through SP4
Description The issue allows attackers to gain privileges by storing old and new passwords in cleartext in the DefaultAuditRecorder.log file when configuration auditing is enabled and a password change occurs.
Recommendations For BEA WebLogic Server and WebLogic Express versions 8.1 through SP4, consider disabling configuration auditing until a fix is available to prevent cleartext password storage in the DefaultAuditRecorder.log file.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0426

Affected Products

Bea Weblogic Server
Weblogic Express