|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA10606] BEA WebLogic Password Exposure Weakness
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Tue Jan 13 2004 - 07:39:31 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
BEA WebLogic Password Exposure Weakness
SECUNIA ADVISORY ID:
SA10606
VERIFY ADVISORY:
http://www.secunia.com/advisories/10606/
CRITICAL:
Not critical
IMPACT:
Exposure of sensitive information
WHERE:
Local system
SOFTWARE:
BEA WebLogic Server 8.x
BEA WebLogic Express 8.x
DESCRIPTION:
BEA has reported a weakness in BEA WebLogic Server and Express
allowing malicious people to see a password when it is entered.
The problem is that the password is echoed to the screen when using
Ant tasks "wldeploy", "wlserver", and "wlconfig". The password will
also be logged to the Ant log files.
The weakness affects BEA WebLogic Server and Express 8.1 Service Pack
1.
SOLUTION:
Apply Service Pack 2.
http://commerce.beasys.com/downloads/weblogic_server.jsp#wls
ORIGINAL ADVISORY:
http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_46.00.jsp
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://www.secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://www.secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]