BEA WebLogic Incorrect Operator...

- AV AC AU C I A
发布: 2004-01-27
修订: 2025-04-13

BEA WebLogic Server and WebLogic Express have been reported prone to a vulnerability that may allow server Operators to view sensitive credentials. The issue is reported to exist because the Operator role is erroneously assigned access to MBean attributes that contain user passwords. An attacker, who is a member of the Operator role, may potentially exploit this vulnerability to disclose sensitive user credentials.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息