[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-2464Date: (C)2006-05-19   (M)2023-12-22


stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the password by viewing a local display.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1016094
SECUNIA-20130
ADV-2006-1828
BEA06-121.00
weblogic-stopweblogic-password-disclosure(26467)

CPE    5
cpe:/a:bea:weblogic_server:8.1:sp1
cpe:/a:bea:weblogic_server:8.1:sp2
cpe:/a:bea:weblogic_server:8.1:sp3
cpe:/a:bea:weblogic_server:8.1
...

© SecPod Technologies