Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BEA WebLogic Local Password Disclosure Vulnerability

Reportedly WebLogic Server and Express are prone to a local username/password disclosure vulnerability. This issue is due to a design error that implements certain internal methods that can reveal the username and passwords that were used to boot the system.

This issue will allow a local user with the ability to authenticate using the username and password that were used to boot the system; the username and password will necessarily correspond to an administrator.







 

Privacy Statement
Copyright 2009, SecurityFocus