BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
BID:9405
Info
BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
| Bugtraq ID: | 9405 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 12 2004 12:00AM |
| Updated: | Jan 12 2004 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 1 BEA Systems WebLogic Server for Win32 8.1 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems WebLogic Express for Win32 8.1 SP 1 BEA Systems WebLogic Express for Win32 8.1 BEA Systems WebLogic Express 8.1 SP 1 BEA Systems WebLogic Express 8.1 |
| Not Vulnerable: |
BEA Systems WebLogic Server for Win32 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems WebLogic Express for Win32 8.1 SP 2 BEA Systems WebLogic Express 8.1 SP 2 |
Discussion
BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
BEA WebLogic Server and Express may allow the administrator password to be displayed in plain text when using Ant tasks. The password may be displayed either on the screen or in log files.
BEA WebLogic Server and Express may allow the administrator password to be displayed in plain text when using Ant tasks. The password may be displayed either on the screen or in log files.
Exploit / POC
BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
Solution:
BEA Systems has addressed this issue in WebLogic Server and WebLogic Express Service Pack 2. See the referenced advisory for download instructions.
Solution:
BEA Systems has addressed this issue in WebLogic Server and WebLogic Express Service Pack 2. See the referenced advisory for download instructions.
References
BEA WebLogic Ant Tasks Administrative Password Exposure Vulnerability
References:
References:
- SECURITY ADVISORY (BEA04-46.00) (BEA Systems)