CVE-2007-0409

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://dev2dev.bea.com/pub/advisory/203 - Patch, Vendor Advisory () http://dev2dev.bea.com/pub/advisory/203 - Patch, Vendor Advisory
References () http://osvdb.org/38501 - () http://osvdb.org/38501 -
References () http://secunia.com/advisories/23750 - () http://secunia.com/advisories/23750 -
References () http://securitytracker.com/id?1017525 - () http://securitytracker.com/id?1017525 -
References () http://www.securityfocus.com/bid/22082 - () http://www.securityfocus.com/bid/22082 -
References () http://www.vupen.com/english/advisories/2007/0213 - () http://www.vupen.com/english/advisories/2007/0213 -

Information

Published : 2007-01-23 00:28

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0409

Mitre link : CVE-2007-0409

CVE.ORG link : CVE-2007-0409


JSON object : View

Products Affected

bea

  • weblogic_server