VulnerabilityModified
CVE-2004-1758
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.
MEDIUM 4.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jspPatch, Vendor Advisory
- http://secunia.com/advisories/11357
- http://securitytracker.com/id?1009764
- http://www.kb.cert.org/vuls/id/920238Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/5297
- http://www.securityfocus.com/bid/10131Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15860
- http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jspPatch, Vendor Advisory
- http://secunia.com/advisories/11357
- http://securitytracker.com/id?1009764
- http://www.kb.cert.org/vuls/id/920238Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/5297
- http://www.securityfocus.com/bid/10131Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15860
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.