CVE-2006-0426: High severity Bea WebLogic Server vulnerability
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0426?
CVE-2006-0426 is considered a high severity vulnerability due to the exposure of sensitive information in cleartext.
How do I fix CVE-2006-0426?
To fix CVE-2006-0426, disable configuration auditing or ensure that sensitive data is not logged in cleartext.
What software versions are affected by CVE-2006-0426?
CVE-2006-0426 affects BEA WebLogic Server and WebLogic Express versions 8.1 through SP4.
What information is leaked in CVE-2006-0426?
CVE-2006-0426 leaks both old and new passwords in cleartext within the DefaultAuditRecorder.log file.
Can attackers exploit CVE-2006-0426 remotely?
Yes, attackers can potentially exploit CVE-2006-0426 remotely if they have access to the logged files containing sensitive information.