CVE-2007-2698

BEA WebLogic Server 9.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration creation, which allows remote attackers to obtain sensitive credential information.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36071
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018057
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1815
Patch, Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/230
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34286

Scores

EPSS 0.0031
EPSS Percentile 54.5%

Details

Status published
Products (1)
bea/weblogic_server 9.0
Published May 16, 2007
Tracked Since Feb 18, 2026