CVE-2004-0652
Summary
| CVE | CVE-2004-0652 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-08-06 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Server | 7.0 | All | All | All |
| Application | Bea | Weblogic Server | 7.0 | All | express | All |
| Application | Bea | Weblogic Server | 7.0 | All | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp3 | win32 | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | All | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | express | All |
| Application | Bea | Weblogic Server | 7.0 | sp4 | win32 | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | All | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | All | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp2 | win32 | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp3 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp3 | express | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp4 | All | All |
| Application | Bea | Weblogic Server | 7.0.0.1 | sp4 | express | All |
| Application | Bea | Weblogic Server | 8.1 | All | All | All |
| Application | Bea | Weblogic Server | 8.1 | All | express | All |
| Application | Bea | Weblogic Server | 8.1 | All | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp1 | win32 | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | express | All |
| Application | Bea | Weblogic Server | 8.1 | sp2 | win32 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Vulnerability Note VU#352110 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| SecurityTracker.com Archives - BEA WebLogic May Disclose Administrative Password in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| www.osvdb.org/5296 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - BEA WebLogic Exposure of Administrative Credentials | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories & Notifications | af854a3a-2127-422b-91ae-364da2661108 | dev2dev.bea.com | |
| BEA WebLogic Local Password Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.