SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5576

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls…

MEDIUM 6.8EPSS 1.00%

Does this matter?

Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.

Description

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.

CVSS 2.0
6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
bea/tuxedo · bea/weblogic integration · bea/weblogic server · bea/weblogic workshop · oracle/weblogic portal
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.