CVE-2006-2469: High severity Bea WebLogic Server vulnerability
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2469?
CVE-2006-2469 has a medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2006-2469?
To address CVE-2006-2469, ensure that you upgrade to the latest patched version of the affected WebLogic Server software.
What versions of Oracle WebLogic Server are affected by CVE-2006-2469?
CVE-2006-2469 affects Oracle WebLogic Server versions 6.1 (up to SP7), 7.0 (up to SP6), 8.1 (up to SP5), and 9.0.
What types of data are compromised in CVE-2006-2469?
CVE-2006-2469 can result in the leakage of usernames and passwords stored in cleartext in server logs.
What are the potential risks of exploiting CVE-2006-2469?
Exploiting CVE-2006-2469 can allow attackers to gain unauthorized access and privileges over the affected web applications.