BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Link | Tags |
---|---|
http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp | patch vendor advisory |
http://www.securityfocus.com/bid/6719 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11220 | vdb entry |