| Vulnerability Name: | CVE-2007-2698 (CCN-34286) | ||||||||
| Assigned: | 2007-05-15 | ||||||||
| Published: | 2007-05-15 | ||||||||
| Updated: | 2017-07-29 | ||||||||
| Summary: | The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration creation, which allows remote attackers to obtain sensitive credential information. The vendor has issued product updates to addresses these issues: BEA WebLogic Server patches: http://commerce.bea.com/showallversions.jsp?family=WLS BEA WebLogic Platform patches: http://commerce.bea.com/showallversions.jsp?family=WLP | ||||||||
| CVSS v3 Severity: | 4.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-2698 Source: BEA Type: Patch, Vendor Advisory BEA07-162.00 Source: OSVDB Type: UNKNOWN 36071 Source: CCN Type: SECTRACK ID: 1018057 BEA WebLogic Server Multiple Bugs Let Remote Users Deny Service, Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1018057 Source: CCN Type: OSVDB ID: 36071 BEA WebLogic Server Administration Console Config Creation Remote Cleartext Credential Disclosure Source: CCN Type: BID-23979 Multiple BEA WebLogic Applications Multiple Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-1815 Source: XF Type: UNKNOWN weblogic-config-information-disclosure(34286) Source: XF Type: UNKNOWN weblogic-config-information-disclosure(34286) Source: CCN Type: BEA07-162.00 The WebLogic console may display certain Web Service sensitive attributes in clear text | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||