First published: Tue Apr 13 2004(Updated: )
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp1 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp2 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp3 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp4 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp5 | |
Oracle WebLogic Server | =6.1-sp6 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp1 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp2 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp3 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =7.0-sp4 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp1 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 | |
Oracle WebLogic Server | =8.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1758 is considered a high severity vulnerability due to the exposure of database credentials in plaintext.
To fix CVE-2004-1758, you should upgrade to a fixed version of BEA WebLogic Server that addresses the plaintext storage issue of JDBC connection pool credentials.
CVE-2004-1758 affects BEA WebLogic Server versions 6.1 up to SP6, 7.0 up to SP4, and 8.1 up to SP2.
If CVE-2004-1758 is not addressed, local users may gain unauthorized access to sensitive database information, leading to potential privilege escalation.
Mitigating CVE-2004-1758 without upgrading is challenging, but you can limit local user access to the configuration files where credentials are stored.