1.5

CVE-2007-0409

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bea ≫ Weblogic Server Update sp6 Version <= 7.0
Bea ≫ Weblogic Server Update sp4 Version <= 8.1
Bea ≫ Weblogic Server Version 7.0
Bea ≫ Weblogic Server Version 8.1
Bea ≫ Weblogic Server Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.199
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 1.5 2.7 2.9
AV:L/AC:M/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/23750
http://www.securityfocus.com/bid/22082
http://www.vupen.com/english/advisories/2007/0213
http://dev2dev.bea.com/pub/advisory/203
Patch
Vendor Advisory
http://osvdb.org/38501
http://securitytracker.com/id?1017525