7.5

CVE-2006-0426

BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Version 8.1 Update sp1
Bea ≫ Weblogic Server Version 8.1 Update sp1 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp2
Bea ≫ Weblogic Server Version 8.1 Update sp2 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp3
Bea ≫ Weblogic Server Version 8.1 Update sp3 Edition express
Bea ≫ Weblogic Server Version 8.1 Update sp4
Bea ≫ Weblogic Server Version 8.1 Update sp4 Edition express
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securitytracker.com/id?1015528
Patch
http://www.securityfocus.com/bid/16358
http://www.vupen.com/english/advisories/2006/0313
http://secunia.com/advisories/18592
Patch
Vendor Advisory
http://dev2dev.bea.com/pub/advisory/170
Patch
Vendor Advisory
http://www.osvdb.org/22775
https://exchange.xforce.ibmcloud.com/vulnerabilities/24290