5
CVSSv2

CVE-2003-1222

Published: 31/12/2003 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

BEA Weblogic Express and Server 8.0 up to and including 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow malicious users to obtain the password.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 8.1