BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
BID:4733
Info
BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
| Bugtraq ID: | 4733 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 10 2002 12:00AM |
| Updated: | May 10 2002 12:00AM |
| Credit: | Credited to Fannie Mae. |
| Vulnerable: |
BEA Systems Weblogic Server 5.1 SP 9 BEA Systems Weblogic Server 5.1 SP 8 BEA Systems Weblogic Server 5.1 SP 7 BEA Systems Weblogic Server 5.1 SP 6 BEA Systems Weblogic Server 5.1 SP 5 BEA Systems Weblogic Server 5.1 SP 4 BEA Systems Weblogic Server 5.1 SP 3 BEA Systems Weblogic Server 5.1 SP 2 BEA Systems Weblogic Server 5.1 SP 12 BEA Systems Weblogic Server 5.1 SP 11 BEA Systems Weblogic Server 5.1 SP 10 BEA Systems Weblogic Server 5.1 SP 1 BEA Systems Weblogic Server 5.1 BEA Systems WebLogic Express 5.1 SP 9 BEA Systems WebLogic Express 5.1 SP 8 BEA Systems WebLogic Express 5.1 SP 7 BEA Systems WebLogic Express 5.1 SP 6 BEA Systems WebLogic Express 5.1 SP 5 BEA Systems WebLogic Express 5.1 SP 4 BEA Systems WebLogic Express 5.1 SP 3 BEA Systems WebLogic Express 5.1 SP 2 BEA Systems WebLogic Express 5.1 SP 12 BEA Systems WebLogic Express 5.1 SP 11 BEA Systems WebLogic Express 5.1 SP 10 BEA Systems WebLogic Express 5.1 SP 1 BEA Systems WebLogic Express 5.1 |
| Not Vulnerable: | |
Discussion
BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
BEA Systems WebLogic Server is an enterprise level web and wireless application server for Microsoft Windows and most Unix and Linux distributions. BEA WebLogic Express provides a platform for serving dynamic data to web and wireless applications.
The SNMP Agent is a Java program that enables the administrator to monitor the status of the server remotely. The agent is started with a command that contains the WebLogic server password. As the password is supplied unencrypted, anyone with the ability to list processes is able to view the password.
BEA Systems WebLogic Server is an enterprise level web and wireless application server for Microsoft Windows and most Unix and Linux distributions. BEA WebLogic Express provides a platform for serving dynamic data to web and wireless applications.
The SNMP Agent is a Java program that enables the administrator to monitor the status of the server remotely. The agent is started with a command that contains the WebLogic server password. As the password is supplied unencrypted, anyone with the ability to list processes is able to view the password.
Exploit / POC
BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
Solution:
BEA Systems has released a fix for this issue. Please note that the appropriate service pack must be installed in order to apply the patch. For BEA Systems WebLogic Express 5.1 SP 12:
BEA Systems WebLogic Express 5.1 SP 12
BEA Systems WebLogic Express 5.1
BEA Systems Weblogic Server 5.1 SP 12
BEA Systems Weblogic Server 5.1
Solution:
BEA Systems has released a fix for this issue. Please note that the appropriate service pack must be installed in order to apply the patch. For BEA Systems WebLogic Express 5.1 SP 12:
BEA Systems WebLogic Express 5.1 SP 12
-
BEA Systems CR069685_510sp12.jar
ftp://ftpna/pub/releases/security/CR069685_510sp12.jar
BEA Systems WebLogic Express 5.1
-
BEA Systems CR069685_510sp12.jar
ftp://ftpna/pub/releases/security/CR069685_510sp12.jar
BEA Systems Weblogic Server 5.1 SP 12
-
BEA Systems CR069685_510sp12.jar
ftp://ftpna/pub/releases/security/CR069685_510sp12.jar
BEA Systems Weblogic Server 5.1
-
BEA Systems CR069685_510sp12.jar
ftp://ftpna/pub/releases/security/CR069685_510sp12.jar
References
BEA Systems WebLogic Server and Express Password Disclosure Vulnerability
References:
References:
- SECURITY ADVISORY (BEA02-18.00) (BEA Systems)
- WebLogic Server Product Homepage (Oracle)