1.5 CVE-2007-0409

Patch
 

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
https://nvd.nist.gov/vuln/detail/CVE-2007-0409

Categories

CWE-NVD-Other

References

BEA Patch

BEA07-136.00
Patch Vendor Advisory

BID

OSVDB

SECTRACK

SECUNIA

VUPEN


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:* <= 7.0
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:* <= 8.1
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*


REMEDIATION


Patch

Url
BEA07-136.00


EXPLOITS


Exploit-db.com

id description date
No known exploits

Other (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry


MITRE