CVE Vulnerabilities

CVE-2006-2469

Published: May 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
Weblogic_serverBea6.0-sp6 (including)6.0-sp6 (including)
Weblogic_serverBea6.1 (including)6.1 (including)
Weblogic_serverBea6.1-sp1 (including)6.1-sp1 (including)
Weblogic_serverBea6.1-sp2 (including)6.1-sp2 (including)
Weblogic_serverBea6.1-sp3 (including)6.1-sp3 (including)
Weblogic_serverBea6.1-sp4 (including)6.1-sp4 (including)
Weblogic_serverBea6.1-sp5 (including)6.1-sp5 (including)
Weblogic_serverBea7.0 (including)7.0 (including)
Weblogic_serverBea7.0-sp1 (including)7.0-sp1 (including)
Weblogic_serverBea7.0-sp2 (including)7.0-sp2 (including)
Weblogic_serverBea7.0-sp3 (including)7.0-sp3 (including)
Weblogic_serverBea7.0-sp4 (including)7.0-sp4 (including)
Weblogic_serverBea7.0-sp5 (including)7.0-sp5 (including)
Weblogic_serverBea8.1 (including)8.1 (including)
Weblogic_serverBea8.1-sp1 (including)8.1-sp1 (including)
Weblogic_serverBea8.1-sp2 (including)8.1-sp2 (including)
Weblogic_serverBea8.1-sp3 (including)8.1-sp3 (including)
Weblogic_serverBea8.1-sp4 (including)8.1-sp4 (including)
Weblogic_serverBea9.0 (including)9.0 (including)

References