2.1
CVE-2004-2321
- EPSS 0.21%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:09:26
- Erkennungen
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 8.1 Update sp1
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition win32
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.111 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
http://dev2dev.bea.com/pub/advisory/1
http://www.securityfocus.com/bid/9505
http://www.securitytracker.com/alerts/2004/Jan/1008867.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/14962