CVE-2004-0712Weblogic Server vulnerability

3 documents3 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 74.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 27
Latest updateApr 29

Description

The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-95ff-4qr3-g2fv: The configuration tools (1) config2022-04-29
CVEList
CVE-2004-0712: The configuration tools (1) config2004-07-21
CVE-2004-0712 — BEA Weblogic Server vulnerability | cvebase