CVE-2005-4755: Low severity oracle weblogic server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key passphrase in cleartext (2) on a terminal or (3) in a log file, which might allow local users to obtain cryptographic keys.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4755?
CVE-2005-4755 has a medium severity level due to the risk of exposing sensitive private key passphrases in cleartext.
How do I fix CVE-2005-4755?
To fix CVE-2005-4755, ensure that the private key passphrase is stored securely and not in cleartext.
Which versions are affected by CVE-2005-4755?
CVE-2005-4755 affects BEA WebLogic Server and WebLogic Express versions 8.1 and earlier, specifically up to SP3.
What is the primary risk associated with CVE-2005-4755?
The primary risk of CVE-2005-4755 is unauthorized access to encrypted communications due to exposed SSL private key passphrases.
Is CVE-2005-4755 still relevant today?
While CVE-2005-4755 pertains to older software versions, it is relevant for organizations still using these vulnerable systems.