VulnerabilityModified
CVE-2004-2321
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
LOW 2.1EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Affected
- bea/weblogic server
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/9505Patch
- http://www.securitytracker.com/alerts/2004/Jan/1008867.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14962
- http://dev2dev.bea.com/pub/advisory/1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/9505Patch
- http://www.securitytracker.com/alerts/2004/Jan/1008867.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14962
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.