CVE-2005-4761: Low severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D option is used.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4761?
CVE-2005-4761 has a medium severity rating due to the potential exposure of sensitive information in logs.
How do I fix CVE-2005-4761?
To fix CVE-2005-4761, avoid using the -D option with sensitive credentials in your Java command line or upgrade to a patched version of WebLogic Server.
Which WebLogic Server versions are affected by CVE-2005-4761?
CVE-2005-4761 affects BEA WebLogic Server versions 6.1 SP7 and earlier, 7.0 SP5 and earlier, and 8.1 SP4 and earlier.
What kind of information can be exposed due to CVE-2005-4761?
CVE-2005-4761 can expose sensitive information such as passwords or keyphrases in server log files.
Is CVE-2005-4761 a client-side or server-side vulnerability?
CVE-2005-4761 is a server-side vulnerability that impacts how sensitive data is logged during server startup.