CVE-2003-1437: Low severity HP HP-UX vulnerability
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1437?
CVE-2003-1437 is considered a high severity vulnerability due to the risk of local users gaining access to sensitive passwords stored in plaintext.
How do I fix CVE-2003-1437?
To fix CVE-2003-1437, it is recommended to update to a patched version of BEA WebLogic Server that properly secures stored passwords.
Which versions of WebLogic Server are affected by CVE-2003-1437?
CVE-2003-1437 affects BEA WebLogic Express and WebLogic Server versions 7.0 and 7.0.0.1.
What is the impact of CVE-2003-1437 on data security?
The impact of CVE-2003-1437 on data security includes unauthorized access to sensitive information since passwords are stored in plaintext.
Who can exploit CVE-2003-1437?
CVE-2003-1437 can be exploited by local users who have access to the system where the vulnerable WebLogic Server is installed.