CVE-2003-1437
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD
Description
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Affected (8)
Products: Bea: Weblogic Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0.0.1 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | Version 11.11i v1 |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | Version 11.00 |
Ibm Aix | Version 4.3.3 |
Redhat Linux | Version 6.2 |
Sun Solaris | Version 2.6 |
Sun Sunos | Version 5.7 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0.0.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 2000 | All versions |
Microsoft Windows Nt | All versions |
References (6)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.