Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-0426
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0426

Description:
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24290

ST
  1015528

SAID
  Secunia Advisory: SA18592

OSVDB
  22775

BID
  16358

BEA
  http://dev2dev.bea.com/pub/advisory/170


Return to the previous page.