BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.
References
Link | Resource |
---|---|
http://dev2dev.bea.com/pub/advisory/63 | |
http://www.securityfocus.com/bid/9034 | Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-08-16T04:00:00
Updated: 2006-04-04T09:00:00
Reserved: 2005-08-16T00:00:00
Link: CVE-2003-1222
JSON object: View
NVD Information
Status : Analyzed
Published: 2003-12-31T05:00:00.000
Modified: 2008-09-10T19:22:39.290
Link: CVE-2003-1222
JSON object: View
Redhat Information
No data.
CWE