BEA WebLogic Keystore Clear Text Password Storage Vulnerability
BID:6719
Info
BEA WebLogic Keystore Clear Text Password Storage Vulnerability
| Bugtraq ID: | 6719 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2003 12:00AM |
| Updated: | Jan 29 2003 12:00AM |
| Credit: | Vulnerability announced by BEA Systems. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: | |
Discussion
BEA WebLogic Keystore Clear Text Password Storage Vulnerability
It has been reported that BEA WebLogic servers are vulnerable to potential password recovery when keystores are used. In the event that an attacker could gain access to one of these keystores, it would be possible for the attacker to discover authentication information that could result in a potential compromise of communication integrity.
It has been reported that BEA WebLogic servers are vulnerable to potential password recovery when keystores are used. In the event that an attacker could gain access to one of these keystores, it would be possible for the attacker to discover authentication information that could result in a potential compromise of communication integrity.
Exploit / POC
BEA WebLogic Keystore Clear Text Password Storage Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
BEA WebLogic Keystore Clear Text Password Storage Vulnerability
Solution:
BEA has made fixes available. These fixes require upgrading to Service Pack 1 of the respective release chain prior to patch application. See the vendor web page reference for more details.
BEA Systems WebLogic Server for Win32 7.0 SP 1
BEA Systems WebLogic Server for Win32 7.0 .0.1
BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1
BEA Systems WebLogic Server for Win32 7.0
BEA Systems WebLogic Express 7.0 .0.1
BEA Systems WebLogic Express for Win32 7.0 SP 1
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems WebLogic Express for Win32 7.0
BEA Systems WebLogic Express for Win32 7.0 .0.1
BEA Systems WebLogic Express 7.0 .0.1 SP 1
BEA Systems Weblogic Server 7.0 .0.1 SP 1
BEA Systems WebLogic Express 7.0
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems Weblogic Server 7.0
BEA Systems WebLogic Express 7.0 SP 1
Solution:
BEA has made fixes available. These fixes require upgrading to Service Pack 1 of the respective release chain prior to patch application. See the vendor web page reference for more details.
BEA Systems WebLogic Server for Win32 7.0 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Server for Win32 7.0 .0.1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Server for Win32 7.0
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express 7.0 .0.1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express for Win32 7.0 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems Weblogic Server 7.0 .0.1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express for Win32 7.0
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express for Win32 7.0 .0.1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express 7.0 .0.1 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems Weblogic Server 7.0 .0.1 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express 7.0
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems Weblogic Server 7.0 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems Weblogic Server 7.0
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
BEA Systems WebLogic Express 7.0 SP 1
-
BEA Systems CR091911_70sp1.jar
ftp://ftpna.beasys.com/pub/releases/security/CR091911_70sp1.jar
References
BEA WebLogic Keystore Clear Text Password Storage Vulnerability
References:
References:
- SECURITY ADVISORY (BEA03-25.00) (BEA Systems)