Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-0409
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0409

Description:
BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.

CVE Status:
Candidate

References:

ST
  1017525

SAID
  Secunia Advisory: SA23750

OSVDB
  38501

BID
  22082

BEA
  http://dev2dev.bea.com/pub/advisory/203


Return to the previous page.