Lucene search

K
cve[email protected]CVE-2003-1437
HistoryOct 23, 2007 - 1:00 a.m.

CVE-2003-1437

2007-10-2301:00:00
web.nvd.nist.gov
24
cve-2003-1437
bea weblogic
plaintext password
vulnerability
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.

Affected configurations

NVD
Node
hphp-uxMatch11.00
OR
hphp-uxMatch11.11iv1
OR
ibmaixMatch4.3.3
OR
microsoftwindows_2000
OR
microsoftwindows_nt
OR
redhatlinuxMatch6.2i386
OR
redhatlinuxMatch7.1i386
OR
sunsolarisMatch2.6
OR
sunsunosMatch5.7
OR
sunsunosMatch5.8
AND
beaweblogic_serverMatch7.0express
OR
beaweblogic_serverMatch7.0sp1express
OR
beaweblogic_serverMatch7.0.0.1express
OR
beaweblogic_serverMatch7.0.0.1sp1express
Node
hphp-uxMatch11.00
OR
hphp-uxMatch11.11i
OR
ibmaixMatch4.3.3
OR
microsoftwindows_2000
OR
microsoftwindows_nt
OR
redhatlinuxMatch6.2i386
OR
redhatlinuxMatch7.1i386
OR
sunsolarisMatch2.6
OR
sunsunosMatch5.7
OR
sunsunosMatch5.8
AND
beaweblogic_serverMatch7.0
OR
beaweblogic_serverMatch7.0sp1
OR
beaweblogic_serverMatch7.0.0.1
OR
beaweblogic_serverMatch7.0.0.1sp1
Node
microsoftwindows_2000
OR
microsoftwindows_nt
AND
beaweblogic_serverMatch7.0
OR
beaweblogic_serverMatch7.0sp1
OR
beaweblogic_serverMatch7.0.0.1
OR
beaweblogic_serverMatch7.0.0.1sp1

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2003-1437