BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_server | Bea | 8.1-sp1 (including) | 8.1-sp1 (including) |