CVE Vulnerabilities

CVE-2005-4761

Published: Dec 31, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.2 LOW
AV:L/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea 6.1 (including) 6.1 (including)
Weblogic_server Bea 6.1-sp1 (including) 6.1-sp1 (including)
Weblogic_server Bea 6.1-sp2 (including) 6.1-sp2 (including)
Weblogic_server Bea 6.1-sp3 (including) 6.1-sp3 (including)
Weblogic_server Bea 6.1-sp4 (including) 6.1-sp4 (including)
Weblogic_server Bea 6.1-sp5 (including) 6.1-sp5 (including)
Weblogic_server Bea 6.1-sp6 (including) 6.1-sp6 (including)
Weblogic_server Bea 6.1-sp7 (including) 6.1-sp7 (including)
Weblogic_server Bea 7.0 (including) 7.0 (including)
Weblogic_server Bea 7.0-sp1 (including) 7.0-sp1 (including)
Weblogic_server Bea 7.0-sp2 (including) 7.0-sp2 (including)
Weblogic_server Bea 7.0-sp3 (including) 7.0-sp3 (including)
Weblogic_server Bea 7.0-sp4 (including) 7.0-sp4 (including)
Weblogic_server Bea 7.0-sp5 (including) 7.0-sp5 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)
Weblogic_server Bea 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_server Bea 8.1-sp2 (including) 8.1-sp2 (including)
Weblogic_server Bea 8.1-sp3 (including) 8.1-sp3 (including)
Weblogic_server Bea 8.1-sp4 (including) 8.1-sp4 (including)

References