CVE-2003-1224: Low severity Bea WebLogic Server vulnerability
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1224?
CVE-2003-1224 is classified as a medium severity vulnerability due to sensitive information exposure.
How do I fix CVE-2003-1224?
To fix CVE-2003-1224, ensure to update to a version of WebLogic Server that does not display passwords in cleartext.
What impact can CVE-2003-1224 have on my system?
CVE-2003-1224 allows attackers to read a user's password through physical observation, compromising user account integrity.
Which versions are affected by CVE-2003-1224?
CVE-2003-1224 affects BEA WebLogic Server and Express version 7.0 and its various service packs.
Is CVE-2003-1224 common among WebLogic Server installations?
Yes, CVE-2003-1224 is a known vulnerability affecting installations of WebLogic Server version 7.0, making it relatively common.