CVE Vulnerabilities

CVE-2006-0427

Published: Jan 25, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea 8.1-sp1 (including) 8.1-sp1 (including)
Weblogic_server Bea 8.1-sp2 (including) 8.1-sp2 (including)
Weblogic_server Bea 8.1-sp3 (including) 8.1-sp3 (including)
Weblogic_server Bea 8.1-sp4 (including) 8.1-sp4 (including)
Weblogic_server Bea 8.1-sp5 (including) 8.1-sp5 (including)
Weblogic_server Bea 9.0-sp1 (including) 9.0-sp1 (including)
Weblogic_server Bea 9.0-sp2 (including) 9.0-sp2 (including)
Weblogic_server Bea 9.0-sp3 (including) 9.0-sp3 (including)
Weblogic_server Bea 9.0-sp4 (including) 9.0-sp4 (including)
Weblogic_server Bea 9.0-sp5 (including) 9.0-sp5 (including)

References