Vulnerability Name: | CCN-40705 | ||||||
Published: | 2008-02-19 | ||||||
Updated: | 2008-02-19 | ||||||
Summary: | BEA WebLogic Portal could allow a remote attacker to obtain sensitive information, caused by the storing of passwords in cleartext in the config.xml file. If the RDBMS Authentication provider has been configured, an attacker could exploit this vulnerability to display the password to gain unauthorized access to the database and obtain sensitive information. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: SA29041 BEA WebLogic Products Multiple Vulnerabilities Source: CCN Type: BID-27893 BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple Vulnerabilities Source: XF Type: UNKNOWN weblogic-portal-config-info-disclosure(40705) Source: CCN Type: BEA08-110.01 Cleartext database password in the config.xml file | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |