First published: Wed Dec 31 2003(Updated: )
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp1 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp2 | |
Oracle WebLogic Server | =7.0.0.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1225 is classified as a medium severity vulnerability due to the exposure of cleartext passwords.
To fix CVE-2003-1225, you should upgrade to a version of WebLogic Server that addresses this vulnerability.
CVE-2003-1225 affects BEA WebLogic Server and Express versions 7.0 and 7.0.0.1, including all service packs up to 7.0-sp4.
CVE-2003-1225 requires local access to the system to exploit the stored passwords in cleartext.
The impact of CVE-2003-1225 includes potential unauthorized access to sensitive data due to the exposure of credentials in cleartext.