CVE Vulnerabilities

CVE-2006-0423

Published: Jan 25, 2006 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.

Affected Software

Name Vendor Start Version End Version
Weblogic_portal Oracle 8.1 (including) 8.1 (including)
Weblogic_portal Oracle 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_portal Oracle 8.1-sp2 (including) 8.1-sp2 (including)
Weblogic_portal Oracle 8.1-sp3 (including) 8.1-sp3 (including)

References