CVE-2004-1758: Medium severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1758?
CVE-2004-1758 is considered a high severity vulnerability due to the exposure of database credentials in plaintext.
How do I fix CVE-2004-1758?
To fix CVE-2004-1758, you should upgrade to a fixed version of BEA WebLogic Server that addresses the plaintext storage issue of JDBC connection pool credentials.
What versions of WebLogic Server are affected by CVE-2004-1758?
CVE-2004-1758 affects BEA WebLogic Server versions 6.1 up to SP6, 7.0 up to SP4, and 8.1 up to SP2.
What are the risks of not addressing CVE-2004-1758?
If CVE-2004-1758 is not addressed, local users may gain unauthorized access to sensitive database information, leading to potential privilege escalation.
Can I mitigate CVE-2004-1758 without upgrading?
Mitigating CVE-2004-1758 without upgrading is challenging, but you can limit local user access to the configuration files where credentials are stored.