CVE-2004-2321: Low severity bea weblogic server vulnerability
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2321?
CVE-2004-2321 is rated as a medium severity vulnerability due to its potential to allow local users to obtain sensitive information.
How do I fix CVE-2004-2321?
To fix CVE-2004-2321, upgrade to BEA WebLogic Server and Express version 8.1 SP2 or later.
Who is affected by CVE-2004-2321?
CVE-2004-2321 affects local users in the Operator role on BEA WebLogic Server and Express versions 8.1 SP1 and earlier.
What information can be exposed due to CVE-2004-2321?
CVE-2004-2321 can expose administrator passwords via MBean attributes such as ServerStartMBean.Password and NodeManagerMBean.CertificatePassword.
What types of systems are vulnerable to CVE-2004-2321?
Systems running BEA WebLogic Server and Express version 8.1 SP1 or earlier are vulnerable to CVE-2004-2321.