7.5
CVE-2006-0426
- EPSS 2.04%
- Veröffentlicht 25.01.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:20:35
- Erkennungen
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 8.1 Update sp1
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp2
Bea ≫ Weblogic Server Version 8.1 Update sp2 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp3
Bea ≫ Weblogic Server Version 8.1 Update sp3 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp4
Bea ≫ Weblogic Server Version 8.1 Update sp4 Edition express
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.04% | 0.789 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://securitytracker.com/id?1015528
http://www.securityfocus.com/bid/16358
http://www.vupen.com/english/advisories/2006/0313
http://secunia.com/advisories/18592
http://dev2dev.bea.com/pub/advisory/170
http://www.osvdb.org/22775
https://exchange.xforce.ibmcloud.com/vulnerabilities/24290