A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges.
Link | Tags |
---|---|
http://secunia.com/advisories/20130 | third party advisory vendor advisory |
http://securitytracker.com/id?1016101 | vdb entry |
http://www.vupen.com/english/advisories/2006/1828 | vdb entry |
http://dev2dev.bea.com/pub/advisory/193 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26460 | vdb entry |