Total vulnerabilities in the database
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
Software | From | Fixed in |
---|---|---|
bea / weblogic_server | 7.0-sp2 | 7.0-sp2.x |
bea / weblogic_server | 7.0 | 7.0.x |
bea / weblogic_server | 7.0.0.1-sp1 | 7.0.0.1-sp1.x |
bea / weblogic_server | 7.0.0.1 | 7.0.0.1.x |
bea / weblogic_server | 7.0.0.1-sp2 | 7.0.0.1-sp2.x |
bea / weblogic_server | 7.0-sp4 | 7.0-sp4.x |
bea / weblogic_server | 7.0-sp1 | 7.0-sp1.x |