CVE Vulnerabilities

CVE-2007-0409

Published: Jan 23, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.5 LOW
AV:L/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.

Affected Software

NameVendorStart VersionEnd Version
Weblogic_serverBea*7.0 (including)
Weblogic_serverBea*8.1 (including)
Weblogic_serverBea7.0 (including)7.0 (including)
Weblogic_serverBea8.1 (including)8.1 (including)
Weblogic_serverBea9.0 (including)9.0 (including)

References