1.5 CVE-2007-0409
Patch
BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
https://nvd.nist.gov/vuln/detail/CVE-2007-0409
Categories
CWE-NVD-Other
References
CPE
cpe | start | end |
---|---|---|
Configuration 1 | ||
cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:*:sp6:*:*:*:*:*:* | <= 7.0 | |
cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:bea:weblogic_server:*:sp4:*:*:*:*:*:* | <= 8.1 | |
cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:* |
REMEDIATION
Patch
Url |
---|
BEA07-136.00 |
EXPLOITS
Exploit-db.com
id | description | date | |
---|---|---|---|
No known exploits |
Other (github, ...)
Url |
---|
No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
id | description | severity |
---|---|---|
No entry |
MITRE
Sherlock® flash
Take a picture of your computer network in a few clicks !
The Sherlock® flash audit solution allows you to perform an audit to strengthen the security of your IT assets. Vulnerability analysis of your physical and virtual equipment. Patch planning by priority level and time available. Detailed and intuitive reporting.
