BEA WebLogic Server/Express...

- AV AC AU C I A
发布: 2004-04-13
修订: 2025-04-13

BEA has reported a weakness affecting WebLogic Server and WebLogic Express. Due to a flaw, vulnerable versions of WebLogic Server/Express may write the clear text database password to a configuration file. This is reported to occur only when a server is configured to employ untargeted JDBC connection pools and have passwords configured. An attacker may harvest the password and use it to gain unauthorized access to the database.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息