PT-2006-3412 · Bea · Bea Weblogic Server

Published

2006-05-19

·

Updated

2017-07-20

·

CVE-2006-2464

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BEA WebLogic Server versions 8.1 before Service Pack 4 BEA WebLogic Server versions 7.0 before Service Pack 6
Description The issue allows local users to obtain the administrator password by viewing a local display when the stopWebLogic.sh script is executed. This occurs because the script displays the administrator password to stdout.
Recommendations For BEA WebLogic Server version 8.1, update to Service Pack 4 or later to resolve the issue. For BEA WebLogic Server version 7.0, update to Service Pack 6 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2464

Affected Products

Bea Weblogic Server