CVE Vulnerabilities

CVE-2007-0409

Published: Jan 23, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.5 LOW
AV:L/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.

Affected Software

Name Vendor Start Version End Version
Weblogic_server Bea * 7.0 (including)
Weblogic_server Bea * 8.1 (including)
Weblogic_server Bea 7.0 (including) 7.0 (including)
Weblogic_server Bea 8.1 (including) 8.1 (including)
Weblogic_server Bea 9.0 (including) 9.0 (including)

References