PT-2007-1884 · Bea · Bea Weblogic Server
Published
2007-01-23
·
Updated
2011-03-08
·
CVE-2007-0413
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BEA WebLogic Server versions 8.1 through 8.1 SP5
Description
The issue allows local users to obtain sensitive information by reading a backup file of config.xml that contains cleartext data after offline editing.
Recommendations
For BEA WebLogic Server versions 8.1 through 8.1 SP5, consider removing or securing the backup file of config.xml after offline editing to prevent unauthorized access to sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bea Weblogic Server