CVE-2007-5576: Infoleak
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5576?
CVE-2007-5576 is classified as a critical vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2007-5576?
To fix CVE-2007-5576, update to the respective patched versions of BEA Tuxedo 8.0 after RP392 or 8.1 after RP293 and WebLogic Enterprise 5.1 after RP174.
What types of attacks are possible due to CVE-2007-5576?
CVE-2007-5576 allows physically proximate attackers to intercept and obtain passwords through command outputs.
What products are affected by CVE-2007-5576?
CVE-2007-5576 affects various versions of BEA Tuxedo and Oracle WebLogic Server, including versions 5.1, 6.1, 7.0, 8.0, and 8.1.
What commands are involved in the exploitation of CVE-2007-5576?
The exploitation of CVE-2007-5576 involves the commands cnsbind, cnsunbind, and cnsls.