{"api_version":"1","generated_at":"2026-07-24T19:36:13+00:00","cve":"CVE-2006-2546","urls":{"html":"https://cve.report/CVE-2006-2546","api":"https://cve.report/api/cve/CVE-2006-2546.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2546","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2546"},"summary":{"title":"CVE-2006-2546","description":"A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-05-23 10:06:00","updated_at":"2017-07-20 01:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/1828","name":"ADV-2006-1828","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016101","name":"1016101","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - WebLogic Server Admin Password Reset Mechanism May Disclose the Password to Local Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20130","name":"20130","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"BEA WebLogic Server/Express Multiple Security Issues - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dev2dev.bea.com/pub/advisory/193","name":"BEA06-131.00","refsource":"BEA","tags":["Patch","Vendor Advisory"],"title":"Recovering admin password can leave cleartext password on disk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26460","name":"weblogic-admin-password-cleartext(26460)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2546","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2546","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2546","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2546","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bea","cpe5":"weblogic_server","cpe6":"8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2546","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20130","refsource":"SECUNIA","url":"http://secunia.com/advisories/20130"},{"name":"1016101","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016101"},{"name":"ADV-2006-1828","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1828"},{"name":"BEA06-131.00","refsource":"BEA","url":"http://dev2dev.bea.com/pub/advisory/193"},{"name":"weblogic-admin-password-cleartext(26460)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26460"}]}},"nvd":{"publishedDate":"2006-05-23 10:06:00","lastModifiedDate":"2017-07-20 01:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bea:weblogic_server:8.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2546","Ordinal":"17858","Title":"CVE-2006-2546","CVE":"CVE-2006-2546","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2546","Ordinal":"1","NoteData":"A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, which could allow attackers to gain privileges.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2546","Ordinal":"2","NoteData":"2006-05-23","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2546","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}