3.5 - Default weblogic account is used

Information

The weblogic user account is the default system administrator account. As a best practice .Delete the default account after defining new admin account with strong password.

An adversary can gain administrator level access by using the well known default credentials.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. In the left pane select Security Realms.
2. On the Summary of Security Realms page select the name of the realm.
3. On the Settings for Realm Name page select Users and Groups > Users
4. Go to New Tab and create a new administrator user
5. Delete the weblogic account