Vulnerabilities > CVE-2005-4761 - Multiple vulnerability in BEA Weblogic Server 6.1/7.0/8.1

047910
CVSS 1.2 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
high complexity
bea

Summary

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used. An attacker must have read access to the server log to see the sensitive values.

Vulnerable Configurations

Part Description Count
Application
Bea
57