CVE-2007-0409

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-01-23 00:28

Updated : 2023-12-10 10:40


NVD link : CVE-2007-0409

Mitre link : CVE-2007-0409

CVE.ORG link : CVE-2007-0409


JSON object : View

Products Affected

bea

  • weblogic_server