BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| oracle / weblogic_portal | 8.1 | 8.1.x |
| oracle / weblogic_portal | 8.1-sp1 | 8.1-sp1.x |
| oracle / weblogic_portal | 8.1-sp2 | 8.1-sp2.x |
| oracle / weblogic_portal | 8.1-sp3 | 8.1-sp3.x |