CVE Vulnerabilities

CVE-2006-0427

Published: Jan 25, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.

Affected Software

NameVendorStart VersionEnd Version
Weblogic_serverBea8.1-sp1 (including)8.1-sp1 (including)
Weblogic_serverBea8.1-sp2 (including)8.1-sp2 (including)
Weblogic_serverBea8.1-sp3 (including)8.1-sp3 (including)
Weblogic_serverBea8.1-sp4 (including)8.1-sp4 (including)
Weblogic_serverBea8.1-sp5 (including)8.1-sp5 (including)
Weblogic_serverBea9.0-sp1 (including)9.0-sp1 (including)
Weblogic_serverBea9.0-sp2 (including)9.0-sp2 (including)
Weblogic_serverBea9.0-sp3 (including)9.0-sp3 (including)
Weblogic_serverBea9.0-sp4 (including)9.0-sp4 (including)
Weblogic_serverBea9.0-sp5 (including)9.0-sp5 (including)

References