WebLogic Multiple Method Cleartext Password Disclosure

low Nessus Plugin ID 11627

Synopsis

The remote web server is affected by information disclosure issues.

Description

The remote web server is running WebLogic 7.0 or 7.0.0.1.

There is a bug in these versions that could allow a local attacker to recover a WebLogic password if the screen of the WebLogic server is visible.

In addition, a local user may be able to view cryptographic secrets, thereby facilitating cracking of encrypted passwords.

Solution

Apply Service Pack 3 or later.

See Also

http://www.nessus.org/u?c3912bcb

Plugin Details

Severity: Low

ID: 11627

File Name: weblogic_cleartext_password.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 5/14/2003

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Low

Base Score: 1.2

Temporal Score: 0.9

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:oracle:weblogic_server

Required KB Items: www/weblogic

Exploit Ease: No exploit is required

Vulnerability Publication Date: 5/13/2003

Reference Information

CVE: CVE-2003-1224, CVE-2003-1225, CVE-2003-1226

BID: 7563, 7587