CVE-2007-0409

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Configurations

Configuration 1

cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:*

Information

Published : 2007-01-23 12:28

Updated : 2011-03-08 02:49


NVD link : CVE-2007-0409

Mitre link : CVE-2007-0409

Products Affected
No products.