VulnerabilityModified
CVE-2007-5576
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls…
MEDIUM 6.8EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- bea/tuxedo · bea/weblogic integration · bea/weblogic server · bea/weblogic workshop · oracle/weblogic portal
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/226
- http://osvdb.org/45478
- http://www.vupen.com/english/advisories/2007/1813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34290
- http://dev2dev.bea.com/pub/advisory/226
- http://osvdb.org/45478
- http://www.vupen.com/english/advisories/2007/1813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34290
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.