CVE-2003-1222: Medium severity Bea WebLogic Server vulnerability
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the WebLogic administrative console and to the domain config.xml file: enforce filesystem permissions so only WebLogic administrators can read config.xml, and restrict console/management network access to trusted administrative IPs to prevent disclosure of foreign JMS provider passwords that may be echoed to the console or stored in cleartext in config.xml.
- Operational
Rotate passwords for any foreign JMS providers configured in BEA Weblogic Express and Server 8.0 through 8.1 SP 1, because those credentials may have been exposed by being echoed to the console or stored in cleartext in config.xml.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1222?
CVE-2003-1222 is considered to be of medium severity due to the potential exposure of sensitive information.
How do I fix CVE-2003-1222?
To fix CVE-2003-1222, ensure that passwords are not echoed to the console and are stored securely, avoiding cleartext in config.xml.
Which versions are affected by CVE-2003-1222?
CVE-2003-1222 affects BEA WebLogic Express and Server versions 8.0 and 8.1 SP1.
What type of information is exposed in CVE-2003-1222?
CVE-2003-1222 exposes the password for the foreign Java Message Service (JMS) provider.
Why is CVE-2003-1222 a concern for security?
CVE-2003-1222 is a concern because it allows attackers to easily obtain passwords stored in cleartext, leading to unauthorized access.