BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 00:25
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://dev2dev.bea.com/pub/advisory/203 - Patch, Vendor Advisory | |
| References | () http://osvdb.org/38501 - | |
| References | () http://secunia.com/advisories/23750 - | |
| References | () http://securitytracker.com/id?1017525 - | |
| References | () http://www.securityfocus.com/bid/22082 - | |
| References | () http://www.vupen.com/english/advisories/2007/0213 - | 
Information
                Published : 2007-01-23 00:28
Updated : 2025-04-09 00:30
NVD link : CVE-2007-0409
Mitre link : CVE-2007-0409
CVE.ORG link : CVE-2007-0409
JSON object : View
Products Affected
                bea
- weblogic_server
CWE
                