CVE-2007-2698: Medium severity Bea WebLogic Server vulnerability
Published May 16, 2007
·Updated
The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration creation, which allows remote attackers to obtain sensitive credential information.
Affected Software
1 affected component
Bea WebLogic Server=9.0
Remediation
Patch Available
Event History
May 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2698?
CVE-2007-2698 is classified as a medium severity vulnerability due to the potential exposure of sensitive credential information.
2
How do I fix CVE-2007-2698?
To fix CVE-2007-2698, upgrade to a patched version of BEA WebLogic Server that resolves this vulnerability.
3
What specific version of WebLogic Server is affected by CVE-2007-2698?
CVE-2007-2698 specifically affects BEA WebLogic Server version 9.0.
4
What are the risks associated with CVE-2007-2698?
The risks associated with CVE-2007-2698 include unauthorized access to sensitive credential information due to plaintext exposure.
5
Who can exploit CVE-2007-2698?
CVE-2007-2698 can potentially be exploited by remote attackers who gain access to the Administration Console.